Uploaded image for project: 'Puppet'
  1. Puppet
  2. PUP-6257

Add --allow-authorization-extensions to puppet cert sign

    XMLWordPrintable

    Details

    • Type: New Feature
    • Status: Closed
    • Priority: Normal
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: PUP 4.6.0
    • Component/s: None
    • Labels:
      None
    • Template:
    • Sub-team:
    • Story Points:
      5
    • Sprint:
      Server Jade 2016-06-29, Server Jade 2016-07-13, Server Jade 2016-07-27

      Description

      In Scope

      • Support a new flag in the "puppet cert sign" tool, "--allow-authorization-extensions"
      • Determine if a cert given to "puppet cert sign" has any extensions under the puppet.1.3 OID arc
      • Fail the signing unless the --allow-authorization-extensions flag is present
      • Audit the cert-related tools in puppet to see if any need to be updated with respect to this work; ca, certificate, certificate-request, certificate-revocation-list. Hopefully they don't need to be updated.
      • Update the internal signing policy in the ruby CA code to allow the new puppet.3 arc (in certificate_authority.rb:323 in puppet)

      Out of Scope

      • Worrying about any extensions other than those under puppet.1.3

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              Unassigned Unassigned
              Reporter:
              nathaniel Nathaniel Smith
              QA Contact:
              Erik Dasher Erik Dasher
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:

                  Zendesk Support