Uploaded image for project: 'Puppet Server'
  1. Puppet Server
  2. SERVER-2285 Update setup actions to also generate the master cert
  3. SERVER-2287

The master cert created by `generate` should have custom extensions for the `cert_status` endpoint auth

    XMLWordPrintable

Details

    • Sub-task
    • Status: Closed
    • Normal
    • Resolution: Fixed
    • None
    • SERVER 5.3.6, SERVER 6.0.0
    • None
    • None
    • Froyo
    • Needs Assessment

    Description

      We currently do not allow any connection to the certificate_status(es) endpoint by default. However, because the CA CLI gem makes heavy use of it, we need to enable the gem to authenticate itself for that endpoint. We should add a custom extension of some kind of the master certificate created by the generate command that can be checked by auth.conf to allow the master cert to use the endpoint, but no other certs.

      Attachments

        Issue Links

          Activity

            People

              maggie Maggie Dreyer
              maggie Maggie Dreyer
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Zendesk Support