Project

General

Profile

Bug #28888

Extra apache configuration needed for cert-based docker syncing

Added by Justin Sherrill 9 months ago. Updated 9 months ago.

Status:
Closed
Priority:
Normal
Category:
Foreman modules
Target version:
-
Difficulty:
Triaged:
No
Bugzilla link:
Fixed in Releases:
Found in Releases:

Description

In order to pull docker content in an authenticated way, some extra config is required in apache under the 443 virtual host:

RequestHeader set SSL_CLIENT_I_DN "%{SSL_CLIENT_I_DN}s"
RequestHeader set SSL_CLIENT_VERIFY "%{SSL_CLIENT_VERIFY}s"
RequestHeader set SSL_SERVER_S_DN_OU "%{SSL_SERVER_S_DN_OU}s"
RequestHeader set SSL_CLIENT_S_DN "%{SSL_CLIENT_S_DN}s"
RequestHeader set SSL_CLIENT_S_DN_X509 "%{SSL_CLIENT_S_DN_X509}s"

We can wrap it in <Location /v2/> ... </Location> if we want to minimize exposure.


Related issues

Blocks Installer - Tracker #28736: Use Pulp 3 for File and Container content in KatelloClosed

Associated revisions

Revision decf125c (diff)
Added by Justin Sherrill 9 months ago

Fixes #28888 - add cert auth for docker registry

History

#1 Updated by The Foreman Bot 9 months ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/theforeman/puppet-katello/pull/319 added

#2 Updated by Justin Sherrill 9 months ago

  • Blocks Tracker #28736: Use Pulp 3 for File and Container content in Katello added

#3 Updated by The Foreman Bot 9 months ago

  • Fixed in Releases 2.0.0 added

#4 Updated by Justin Sherrill 9 months ago

  • Status changed from Ready For Testing to Closed

Also available in: Atom PDF