Project

General

Profile

Actions

Feature #12127

closed

Foreman should verify x509 subject alternative names when authenticating a smart proxy

Added by Timo Goebel over 8 years ago. Updated almost 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Smart Proxy
Target version:
Difficulty:
easy
Triaged:
Fixed in Releases:
Found in Releases:

Description

Foreman should verify the san attributes of the client cert if they are set in the certificate. Currently only the dn is checked.
This helps in a ha environment when using the vipname in the san.

https://github.com/theforeman/foreman/blob/1.10-stable/app/controllers/concerns/foreman/controller/smart_proxy_auth.rb#L49


Related issues 2 (0 open2 closed)

Related to Foreman - Bug #13817: ENC smart proxy validation failsClosedMatthew Ceroni02/19/2016Actions
Has duplicate Foreman - Bug #12126: Foreman should verify x509 subject alternative names when authenticating a smart proxyDuplicateTimo Goebel10/09/2015Actions
Actions

Also available in: Atom PDF