Project

General

Profile

Actions

Bug #12126

closed

Foreman should verify x509 subject alternative names when authenticating a smart proxy

Added by Timo Goebel over 9 years ago. Updated over 9 years ago.

Status:
Duplicate
Priority:
Normal
Assignee:
Category:
Smart Proxy
Target version:
-
Difficulty:
easy
Triaged:
Fixed in Releases:
Found in Releases:

Description

Foreman should verify the san attributes of the client cert if they are set in the certificate. Currently only the dn is checked.
This helps in a ha environment when using the vipname in the san.

https://github.com/theforeman/foreman/blob/1.10-stable/app/controllers/concerns/foreman/controller/smart_proxy_auth.rb#L49


Related issues 1 (0 open1 closed)

Is duplicate of Foreman - Feature #12127: Foreman should verify x509 subject alternative names when authenticating a smart proxyClosedTimo Goebel10/09/2015Actions
Actions

Also available in: Atom PDF