Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

support multiple certificates for root-ca-file and server-cert-file #9012

Merged
merged 2 commits into from
Jul 22, 2024

Conversation

mcalmer
Copy link
Contributor

@mcalmer mcalmer commented Jul 5, 2024

What does this PR change?

Support multiple certificates for root-ca-file and server-cert-file.
First split all files files into single certificates. If multiple certificates are found in root-ca-file or server-cert-file,
use all additional as intermediate CAs.

This means especially for server-cert-file: it must contain the server certificate as the 1st certificate. Additional certificates in the same file are added to intermediate CAs.

GUI diff

No difference.

  • DONE

Documentation

  • No documentation needed: only internal and user invisible changes

  • DONE

Test coverage

  • No tests: already covered

  • DONE

Links

Issue(s): #8983
Port(s): https://github.com/SUSE/spacewalk/pull/24786

  • DONE

Changelogs

Make sure the changelogs entries you are adding are compliant with https://github.com/uyuni-project/uyuni/wiki/Contributing#changelogs and https://github.com/uyuni-project/uyuni/wiki/Contributing#uyuni-projectuyuni-repository

If you don't need a changelog check, please mark this checkbox:

  • No changelog needed

If you uncheck the checkbox after the PR is created, you will need to re-run changelog_test (see below)

Re-run a test

If you need to re-run a test, please mark the related checkbox, it will be unchecked automatically once it has re-run:

  • Re-run test "changelog_test"
  • Re-run test "backend_unittests_pgsql"
  • Re-run test "java_pgsql_tests"
  • Re-run test "schema_migration_test_pgsql"
  • Re-run test "susemanager_unittests"
  • Re-run test "javascript_lint"
  • Re-run test "spacecmd_unittests"

Before you merge

Check How to branch and merge properly!

this makes testing cert chain possible without having the private key
@mcalmer mcalmer requested a review from a team as a code owner July 5, 2024 11:33
@mcalmer mcalmer requested review from m-czernek and cbosdo and removed request for a team July 5, 2024 11:33
Copy link
Contributor

@cbosdo cbosdo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. I wonder if I need to somehow do something similar in https://github.com/uyuni-project/uyuni-tools/blob/main/mgradm/shared/ssl/ssl.go

@cbosdo
Copy link
Contributor

cbosdo commented Jul 5, 2024

LGTM. I wonder if I need to somehow do something similar in https://github.com/uyuni-project/uyuni-tools/blob/main/mgradm/shared/ssl/ssl.go

Answer: the go code already handles that: nothing to do here.

@mcalmer mcalmer added the merge-candidate Meaning it needs to be considered for merging when the master branch is frozen label Jul 10, 2024
@admd admd merged commit 9b0e0e9 into uyuni-project:master Jul 22, 2024
24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
merge-candidate Meaning it needs to be considered for merging when the master branch is frozen
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants