Uploaded image for project: 'Puppet'
  1. Puppet
  2. PUP-9964

Puppet Server CA auth is missing from the list of recognized certificate extensions

    XMLWordPrintable

Details

    • Bug
    • Status: Accepted
    • Normal
    • Resolution: Unresolved
    • PUP 5.5.16, PUP 6.4.3, PUP 6.7.2
    • None
    • None
    • Coremunity
    • Needs Assessment
    • Needs Assessment

    Description

      As part of SERVER-2287, OID 1.3.6.1.4.1.34380.1.3.39 was designated as the certificate extension that allows a certificate to make REST calls to the CA API:

      https://github.com/puppetlabs/puppetserver/blob/6.5.0/src/clj/puppetlabs/puppetserver/certificate_authority.clj#L196-L199

      However, this OID was never added to the list of extensions that Puppet's Ruby code recognizes:

      https://github.com/puppetlabs/puppet/blob/6.7.2/lib/puppet/ssl/oids.rb

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              chuck Charlie Sharpsteen
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:

                Zendesk Support