Project

General

Profile

Actions

Architecture #15513

closed

Make certificate verification in HTTP calls configurable

Added by Alexis Mousset over 5 years ago. Updated over 2 years ago.

Status:
Released
Priority:
N/A
Category:
Agent
Target version:
Effort required:
Name check:
To do
Fix check:
To do
Regression:

Description

Currently all HTTP calls (reporting, inventory, API, etc.) disable certificate validation.

We can make it configurable based on a system variable, to allow users having a certificate infrastructure in place to verify certificates.

This change needs to be done in both techniques and agent scripts.

The default behaviour needs to stay the current one for compatibility.


Subtasks 4 (0 open4 closed)

Architecture #15514: Make certificate verification in HTTP calls configurable - techniquesReleasedNicolas CHARLESActions
Architecture #15518: Make certificate verification in HTTP calls configurable - ncfReleasedNicolas CHARLESActions
Architecture #15516: Add new system variable for certificate validationRejectedActions
Architecture #15517: scala code for handling the system variable and setting it with APIReleasedVincent MEMBRÉActions

Related issues 3 (0 open3 closed)

Related to Rudder - Architecture #15515: Document how to use an existing X509 PKI to secure Rudder node-server communicationRejectedActions
Has duplicate Rudder - User story #11835: Make curl invocation's ignore certificate configurableRejectedActions
Has duplicate Rudder - User story #9624: Add an option to check server certificate when sending inventoryRejectedActions
Actions #1

Updated by Alexis Mousset over 5 years ago

  • Status changed from New to In progress
  • Assignee set to Alexis Mousset
Actions #2

Updated by Alexis Mousset over 5 years ago

  • Status changed from In progress to Pending technical review
  • Assignee changed from Alexis Mousset to Nicolas CHARLES
  • Pull Request set to https://github.com/Normation/rudder-techniques/pull/1498
Actions #3

Updated by Alexis Mousset over 5 years ago

  • Has duplicate User story #11835: Make curl invocation's ignore certificate configurable added
Actions #4

Updated by Alexis Mousset over 5 years ago

  • Has duplicate User story #9624: Add an option to check server certificate when sending inventory added
Actions #5

Updated by Alexis Mousset over 5 years ago

  • Status changed from Pending technical review to Pending release
Actions #6

Updated by Vincent MEMBRÉ about 5 years ago

This bug has been fixed in Rudder 6.0.0~beta1 which was released today.

Actions #7

Updated by Vincent MEMBRÉ about 5 years ago

  • Related to Architecture #15515: Document how to use an existing X509 PKI to secure Rudder node-server communication added
Actions #8

Updated by Vincent MEMBRÉ about 5 years ago

  • Status changed from Pending release to Released
Actions

Also available in: Atom PDF