121 Commits (74dc50a77127edba36984c889c1f7ea49049798a)

Author SHA1 Message Date
R.B. Boyer 409c901f8e test: fix concurrent map access when setting up test vault 6 years ago
R.B. Boyer c7067645dd fix a few leap-year related clock math inaccuracies and failing tests 6 years ago
Kyle Havlovitz 29e4c17b07
connect/ca: fix a potential panic in the Consul provider 6 years ago
Kyle Havlovitz a28ba4687d
connect/ca: return a better error message if the CA isn't fully initialized when signing 6 years ago
Paul Banks 0638e09b6e
connect: agent leaf cert caching improvements (#5091) 6 years ago
Hans Hasselberg 067027230b
connect: add tls config for vault connect ca provider (#5125) 6 years ago
Mitchell Hashimoto f76022fa63 CA Provider Plugins (#4751) 6 years ago
Kyle Havlovitz e8dd89359a
agent: fix formatting 6 years ago
Aestek 25f04fbd21 [Security] Add finer control over script checks (#4715) 6 years ago
Paul Banks 1909a95118 xDS Server Implementation (#4731) 6 years ago
Kyle Havlovitz 57deb28ade connect/ca: tighten up the intermediate signing verification 6 years ago
Kyle Havlovitz 2919519665 connect/ca: add intermediate functions to Vault ca provider 6 years ago
Kyle Havlovitz 52e8652ac5 connect/ca: add intermediate functions to Consul CA provider 6 years ago
Paul Banks 74f2a80a42
Fix CA pruning when CA config uses string durations. (#4669) 6 years ago
Kyle Havlovitz 5c7fbc284d connect/ca: hash the consul provider ID and include isRoot 6 years ago
Kyle Havlovitz c112a72880
connect/ca: some cleanup and reorganizing of the new methods 6 years ago
Kyle Havlovitz 546bdf8663
connect/ca: add Configure/GenerateRoot to provider interface 6 years ago
Siva Prasad 288d350a73
Revert "CA initialization while boostrapping and TestLeader_ChangeServerID fix." (#4497) 6 years ago
Siva Prasad 589b589b53
CA initialization while boostrapping and TestLeader_ChangeServerID fix. (#4493) 6 years ago
Kyle Havlovitz f67a4d59c0
connect/ca: simplify passing of leaf cert TTL 6 years ago
Kyle Havlovitz ce10de036e
connect/ca: check LeafCertTTL when rotating expired roots 6 years ago
Kyle Havlovitz d6ca015a42
connect/ca: add configurable leaf cert TTL 6 years ago
Matt Keeler 677d6dac80 Remove x509 name constraints 7 years ago
Kyle Havlovitz 8c2c9705d9 connect/ca: use weak type decoding in the Vault config parsing 7 years ago
Kyle Havlovitz 050da22473 connect/ca: undo the interface changes and use sign-self-issued in Vault 7 years ago
Kyle Havlovitz 914d9e5e20 connect/ca: add leaf verify check to cross-signing tests 7 years ago
Kyle Havlovitz bc997688e3 connect/ca: update Consul provider to use new cross-sign CSR method 7 years ago
Kyle Havlovitz 8a70ea64a6 connect/ca: update Vault provider to add cross-signing methods 7 years ago
Kyle Havlovitz 6a2fc00997 connect/ca: add URI SAN support to the Vault provider 7 years ago
Kyle Havlovitz 226a59215d connect/ca: fix vault provider URI SANs and test 7 years ago
Kyle Havlovitz 1a8ac686b2 connect/ca: add the Vault CA provider 7 years ago
Paul Banks 51fc48e8a6 Sign certificates valid from 1 minute earlier to avoid failures caused by clock drift 7 years ago
Paul Banks e514570dfa Actually return Intermediate certificates bundled with a leaf! 7 years ago
Kyle Havlovitz ab4a9a94f4
Re-use uint8ToString 7 years ago
Kyle Havlovitz 5683d628c4
Support giving the duration as a string in CA config 7 years ago
Paul Banks 140f3f5a44
Fix logical conflicts with CA refactor 7 years ago
Paul Banks 4aeab3897c
Fixed many tests after rebase. Some still failing and seem unrelated to any connect changes. 7 years ago
Paul Banks 1722734313
Verify trust domain on /authorize calls 7 years ago
Paul Banks b4803eca59
Generate CSR using real trust-domain 7 years ago
Paul Banks 622a475eb1
Add CSR signing verification of service ACL, trust domain and datacenter. 7 years ago
Paul Banks c1f2025d96
Return TrustDomain from CARoots RPC 7 years ago
Kyle Havlovitz e00088e8ee
Rename some of the CA structs/files 7 years ago
Kyle Havlovitz 627aa80d5a
Use provider state table for a global serial index 7 years ago
Kyle Havlovitz 988510f53c
Add test for ca config http endpoint 7 years ago
Kyle Havlovitz de72834b8c
Move connect CA provider to separate package 7 years ago
Paul Banks e0e12e165b
TLS watching integrated into Service with some basic tests. 7 years ago
Paul Banks 90c574ebaa
Wire up agent leaf endpoint to cache framework to support blocking. 7 years ago
Kyle Havlovitz edcfdb37af
Fix some inconsistencies around the CA provider code 7 years ago
Kyle Havlovitz 315b8bf594
Simplify the CAProvider.Sign method 7 years ago
Kyle Havlovitz c6e1b72ccb
Simplify the CA provider interface by moving some logic out 7 years ago