Mariano Cano
|
a7fe0104c4
|
Remove ACME restrictions and add proper template support.
|
2020-07-21 14:18:06 -07:00 |
|
Mariano Cano
|
cf2989a848
|
Add token and subject to K8sSA provisioner to be used in custom
templates.
|
2020-07-21 14:18:06 -07:00 |
|
Mariano Cano
|
71be83b25e
|
Add iss#sub uri in OIDC certificates.
Admin will use the CR template if none is provided.
|
2020-07-21 14:18:06 -07:00 |
|
Mariano Cano
|
c58117b30d
|
Allow to use base64 when defining a template in the ca.json.
|
2020-07-21 14:18:06 -07:00 |
|
Mariano Cano
|
b2ca3176f5
|
Prepend insecure to user and CR variables names.
|
2020-07-21 14:18:06 -07:00 |
|
Mariano Cano
|
b11486f41f
|
Fix option method for template variable.
|
2020-07-21 14:18:06 -07:00 |
|
Mariano Cano
|
04f5053a7a
|
Add template support for x5c.
|
2020-07-21 14:18:06 -07:00 |
|
Mariano Cano
|
eb8886d828
|
Add CR subject as iid default subject.
Add a minimal subject with just a common name to iid provisioners
in case we want to use it.
|
2020-07-21 14:18:06 -07:00 |
|
Mariano Cano
|
e60ea419cc
|
Add template support for gcp provisioner.
|
2020-07-21 14:18:06 -07:00 |
|
Mariano Cano
|
32646c49bf
|
Add templates support to Azure provisioner.
|
2020-07-21 14:18:06 -07:00 |
|
Mariano Cano
|
a44f0ca866
|
Add token payload.
|
2020-07-21 14:18:06 -07:00 |
|
Mariano Cano
|
00fd41a3d0
|
Add template support to K8sSA provisioners.
|
2020-07-21 14:18:06 -07:00 |
|
Mariano Cano
|
13b704aeed
|
Add template support for AWS provisioner.
|
2020-07-21 14:18:05 -07:00 |
|
Mariano Cano
|
49b9aa6e3f
|
Fix log string.
|
2020-07-21 14:18:05 -07:00 |
|
Mariano Cano
|
4795e371bd
|
Add back the support for ca.json DN template.
|
2020-07-21 14:18:05 -07:00 |
|
Mariano Cano
|
e6fed5e0aa
|
Minor fixes and comments.
|
2020-07-21 14:18:05 -07:00 |
|
Mariano Cano
|
81cd288104
|
Enable templates in acme provisioners.
|
2020-07-21 14:18:05 -07:00 |
|
Mariano Cano
|
ca2fb42d68
|
Move options to the provisioner.
|
2020-07-21 14:18:05 -07:00 |
|
Mariano Cano
|
206bc6757a
|
Add initial support for templates in the OIDC provisioner.
|
2020-07-21 14:18:05 -07:00 |
|
Mariano Cano
|
95c3a41bf0
|
Rename UserData to TemplateData and fix unmarshaling.
|
2020-07-21 14:18:04 -07:00 |
|
Mariano Cano
|
9f3acc254b
|
Set the token payload in the JWK provisioner.
|
2020-07-21 14:18:04 -07:00 |
|
Mariano Cano
|
ef0ed0ff95
|
Integrate simple templates in the JWK provisioner.
|
2020-07-21 14:18:04 -07:00 |
|
Mariano Cano
|
d1d9ae42d6
|
Use certificates x509util instead of cli for certificate signing.
|
2020-07-21 14:18:04 -07:00 |
|
Mariano Cano
|
9032018cf2
|
Convert x509util.WithOptions to new modifiers.
|
2020-07-21 14:18:04 -07:00 |
|
Carl Tashian
|
912e298043
|
Whitelist -> Allowlist per https://tools.ietf.org/id/draft-knodel-terminology-01.html
|
2020-07-20 15:42:47 -07:00 |
|
max furman
|
fd05f3249b
|
A few last fixes and tests added for rekey/renew ...
- remove all `renewOrRekey`
- explicitly test difference between renew and rekey (diff pub keys)
- add back tests for renew
|
2020-07-09 12:11:40 -07:00 |
|
Max
|
ea9bc493b8
|
Merge pull request #307 from dharanikumar-s/master
Add support for rekeying Fixes #292
|
2020-07-09 11:39:00 -07:00 |
|
dharanikumar-s
|
57fb0c80cf
|
Removed calculating SubjectKeyIdentifier on Rekey
|
2020-07-08 12:52:53 +05:30 |
|
dharanikumar-s
|
dfda497929
|
Renamed RenewOrRekey to Rekey
|
2020-07-08 11:47:59 +05:30 |
|
dharanikumar-s
|
fe73154a20
|
Corrected misspelling
|
2020-07-05 22:50:02 +05:30 |
|
dharanikumar-s
|
0c21f0ae9e
|
Added error check after GenerateDefaultKeyPair
|
2020-07-05 22:38:45 +05:30 |
|
dharanikumar-s
|
2479371c06
|
Added error check while marshalling public key
|
2020-07-05 22:37:29 +05:30 |
|
dharanikumar-s
|
b368a53149
|
Modified TestAuthority_Renew to TestAuthority_RenewOrRekey
|
2020-07-05 22:17:57 +05:30 |
|
dharanikumar-s
|
c8c3581e2f
|
SubjectKeyIdentifier extention is calculated from public key passed to this function instead of copying from old certificate
|
2020-07-05 22:15:01 +05:30 |
|
dharanikumar-s
|
8f504483ce
|
Added RenewOrRekey function based on @maraino suggestion. RenewOrReky is called from Renew.
|
2020-07-03 15:58:15 +05:30 |
|
dharanikumar-s
|
3813f57b1a
|
Add support for rekeying Fixes #292
|
2020-07-01 19:10:13 +05:30 |
|
Max
|
debce1cec2
|
Merge pull request #299 from smallstep/max/refactor
Refactor
|
2020-06-25 15:32:04 -07:00 |
|
max furman
|
accf1be7e9
|
wip
|
2020-06-25 14:02:24 -07:00 |
|
max furman
|
71d87b4e61
|
wip
|
2020-06-24 23:25:15 -07:00 |
|
max furman
|
d25e7f64c2
|
wip
|
2020-06-24 09:58:40 -07:00 |
|
max furman
|
3636ba3228
|
wip
|
2020-06-23 17:13:39 -07:00 |
|
Mariano Cano
|
39650637d4
|
Merge pull request #297 from smallstep/no-bastion-bastion
Do not return bastion for the configured bastion host.
|
2020-06-23 11:45:25 -07:00 |
|
Mariano Cano
|
fcfc4e9b2b
|
Fix ssh federated template variables.
|
2020-06-23 11:14:26 -07:00 |
|
max furman
|
1951669e13
|
wip
|
2020-06-23 11:10:45 -07:00 |
|
Mariano Cano
|
b0fdd0b2be
|
Do not return bastion for the configured bastion host.
Fixes #296
|
2020-06-19 12:37:08 -07:00 |
|
Mariano Cano
|
ff32746312
|
Add test case for error executing template.
|
2020-06-16 18:21:44 -07:00 |
|
Mariano Cano
|
e3ae751b57
|
Use templates from authority instead of config.
|
2020-06-16 17:57:35 -07:00 |
|
Mariano Cano
|
237baa5169
|
Check for required variables in templates.
Fixes smallstep/cli#232
|
2020-06-16 17:26:54 -07:00 |
|
Mariano Cano
|
6c844a0618
|
Load default templates if no templates are configured.
|
2020-06-16 17:26:18 -07:00 |
|
Max
|
2ebfc73f77
|
Merge pull request #290 from smallstep/max/profileLimit
Update profileLimitDuration validator ...
|
2020-06-16 13:04:34 -07:00 |
|