Project

Profile

Help

Network maintenance. Planio will be observing two scheduled maintenance windows this Tuesday, March 2 and Wednesday, March 3 from 02:00 UTC until 06:00 UTC each in order to perform maintenance on access routers in our primary datacenter. Your account might observe short downtimes during these periods up to several minutes at a time.

Story #4666

As a user I have path checking features for to the X.509 certguard

Added by bmbouter almost 2 years ago. Updated 5 months ago.

Status:
NEW
Priority:
Normal
Assignee:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Platform Release:
Groomed:
Yes
Sprint Candidate:
Tags:
Sprint:
Quarter:

Description

Motivation

It would be very useful for paths to be put into the x.509 extended attributes to see if this client is authorized to access this specific distribution's content. This way whoever is generating the certs (and their expiration dates) determines the access.

Solution

The existing X.509 certguard could automatically be updated to check this correctly. We also need docs with how the openssl tooling can easily make these kind of certs.

How will we ensure path checking is required?

A boolean will be added to the X.509 certguard called path_check_required which will default to False. If True, the certificate check must contain a matching path for the content requested.

History

#1 Updated by bmbouter almost 2 years ago

  • Description updated (diff)

revising with details about how users can configure that path checking is required

#2 Updated by bmbouter almost 2 years ago

  • Description updated (diff)

#3 Updated by bmbouter almost 2 years ago

  • Tags deleted (Pulp 3)

#4 Updated by bmbouter almost 2 years ago

  • Groomed changed from No to Yes
  • Sprint Candidate changed from No to Yes

We should add this to the sprint.

#5 Updated by bmbouter over 1 year ago

  • Sprint set to Sprint 54

These weren't added to Sprint 54, but they were OK'd at sprint planning.

#6 Updated by ttereshc over 1 year ago

  • Sprint changed from Sprint 54 to Sprint 55

#7 Updated by dkliban@redhat.com over 1 year ago

  • Sprint changed from Sprint 55 to Sprint 56

#8 Updated by rchan over 1 year ago

  • Sprint changed from Sprint 56 to Sprint 57

#9 Updated by rchan over 1 year ago

  • Sprint changed from Sprint 57 to Sprint 58

#10 Updated by rchan over 1 year ago

  • Sprint deleted (Sprint 58)

#11 Updated by rchan over 1 year ago

Not moving forward to next Sprint to make room for highest priority Katello blockers.

#12 Updated by rchan about 1 year ago

  • Sprint Candidate deleted (Yes)

#13 Updated by bmbouter 7 months ago

  • Sprint/Milestone deleted (1.0.0 Release)

#14 Updated by dustball 5 months ago

I'm interested in this feature as well, we're serving a large amount of customers with all different kinds of systems.

We want to offer our customers staging for licensed products via a central pulpserver as well and individually allow or deny access to those repositories.

Please register to edit this issue

Also available in: Atom PDF