Project

General

Profile

Actions

Architecture #26942

closed

Add new settings to handle certificate trust

Added by Benoît PECCATTE 3 months ago. Updated 23 days ago.

Status:
Released
Priority:
N/A
Category:
Web - Config management
Target version:
Effort required:
Name check:
To do
Fix check:
To do
Regression:
No

Description

Add 2 new settings in rudder-web.properties that will be generated into 3 new values in policy's rudder.json files.
Here are what the 2 generated values must look like :

  • POLICY_SERVER_CERT_NAME_VALIDATION: boolean, default false
  • POLICY_SERVER_CERT_CA: pem certificate, default empty

Chabge 1 generated property to match

  • POLICY_SERVER_KEY_HASH: list of key hashes, in the form "sha256//Pxjkq/Qlp02j8Q3ti3M1khEaUTL7Dxcz8sLOfGcg5rQ=;sha256//..."

Subtasks 3 (0 open3 closed)

Architecture #26950: Handle certificate trust in rudder-clientReleasedAlexis MoussetActions
Architecture #26975: Generate rudder-client certificate authority before any rudder-client callReleasedAlexis MoussetActions
Architecture #27296: POLICY_SERVER_KEY_HASH must not happen a semicolon when emptyReleasedBenoît PECCATTEActions
Actions

Also available in: Atom PDF