Stefan Berthold
2208b03744
avoid panic when OIDC config is not provided
9 months ago
Stefan Berthold
e6dd211637
acquire DPoP signing key from provisioner
9 months ago
Stefan Berthold
8e0e35532c
Add Wire authz and challenges (OIDC+DPOP)
9 months ago
Mariano Cano
b20af51f32
Upgrade go.step.sm/crypto to use go-jose/v3
10 months ago
Max
d34f0f6a97
Fix linter warnings ( #1634 )
10 months ago
Herman Slatman
f082cbc421
Denormalize provisioner name in SCEP webhook
11 months ago
Herman Slatman
9ebc8779f5
Normalize SCEP provisioner name in webhook body
11 months ago
Herman Slatman
e815864ed8
Add verification of `provisionerName` in test
11 months ago
Herman Slatman
de45d66cdb
Add `provisionerName` to webhook request body
11 months ago
Mariano Cano
49045a1150
Change CommonName validator in JWK
...
This commit changes the common name validator in the JWK provisioner to
accept either the token subject or any of the sans in the token.
11 months ago
Max
9f84f7ce35
Allow for identity certificate signing (in sshSign) by skipping validators ( #1572 )
...
- skip urisValidator for identity certificate signing. Implemented
by building the validator with the context in a hacky way.
12 months ago
Mariano Cano
52baf52f84
Change scep password type to string
...
This commit changes the type of the decrypter key password to string to
be consistent with other passwords in the ca.json
1 year ago
Herman Slatman
c0fbace882
Address review remarks
1 year ago
Herman Slatman
4dc5a688fd
Set SCEP authority options once
1 year ago
Herman Slatman
15c46ebbaa
Switch logic for SCEP initialization around
1 year ago
Herman Slatman
f1da256ca4
Change SCEP authority initialization
1 year ago
Herman Slatman
4554f86f16
Make SCEP decrypter properties use `omitempty`
1 year ago
Herman Slatman
ffe079f31b
Merge branch 'master' into herman/scep-provisioner-decrypter
1 year ago
Mariano Cano
31da66c124
Fix webhooks signature
...
This commit fixes the way webhooks signatures are created. Before this
change, the signature of an empty body was prepended by the body itself.
1 year ago
Herman Slatman
3f3b67e05c
Merge branch 'herman/scep-provisioner-decrypter' into herman/scep-notifying-webhook
1 year ago
Herman Slatman
ba72710e2d
Address code review remarks
1 year ago
Herman Slatman
5f8e0de1c3
Fix duplicate import in SCEP provisioner
1 year ago
Herman Slatman
4fd4227b73
Use shorter SCEP decrypter property names from linkedca
1 year ago
Herman Slatman
5fd70af2c8
Make API responses aware of the new SCEP decrypter properties
1 year ago
Herman Slatman
3ade92f8d5
Support both a decrypter key URI as well as PEM
1 year ago
Herman Slatman
b6c95d7be2
Add additional properties to SCEP notify webhook request body
1 year ago
Herman Slatman
63257e0576
Add full certificate DER bytes to success notification webhook
1 year ago
Herman Slatman
52bc96760b
Add SCEP certificate issuance notification webhook
1 year ago
Herman Slatman
a3c9dd796a
Merge branch 'herman/scep-provisioner-decrypter' of github.com:smallstep/certificates into herman/scep-provisioner-decrypter
1 year ago
Herman Slatman
69a53eec33
Merge branch 'master' into herman/scep-provisioner-decrypter
1 year ago
Dominic Evans
231b5d8406
chore(deps): upgrade github.com/go-chi/chi to v5
...
Upgrade chi to the v5 module path to avoid deprecation warning about v4
and earlier on the old module path.
See https://github.com/go-chi/chi/blob/v4.1.3/go.mod#L1-L4
Signed-off-by: Dominic Evans <dominic.evans@uk.ibm.com>
1 year ago
Max
b7c4ed26fb
Use provisioner name in error message ( #1524 )
1 year ago
Herman Slatman
33e661ce7d
Add a dummy CSR to SCEP request body tests
1 year ago
Herman Slatman
36f1dd70bf
Add CSR to `SCEPCHALLENGE` webhook request body
1 year ago
Herman Slatman
98d015b5c3
Fix linting issues
1 year ago
Herman Slatman
d9f56cdbdc
Merge branch 'master' into herman/scep-provisioner-decrypter
1 year ago
Herman Slatman
9d3b78ae49
Add `excludeIntermediate` to SCEP provisioner
1 year ago
Max
e22166c628
provisionerOptionsToLinkedCA missing template and templateData ( #1520 )
1 year ago
Max
116ff8ed65
bump go.mod to go1.20 and associated linter fixes ( #1518 )
1 year ago
Remi Vichery
82b8e16d7f
Add all AWS identity document certificates
...
* move to use embed instead of a multi-line string
* add test to ensure all certificates are valid
* add test to ensure validity (no expired certificate)
1 year ago
Herman Slatman
e182c620c8
Merge branch 'master' into herman/scep-provisioner-decrypter
1 year ago
Herman Slatman
645b6ffc18
Ensure no prompt is fired for loading provisioner decrypter
1 year ago
Mariano Cano
30ce9e65f7
Write configuration only if encoding succeeds
...
This commit fixes a problem when the ca.json is truncated if the
encoding of the configuration fails. This can happen by adding a new
provisioner with bad template data.
Related to smallstep/cli#994
1 year ago
Herman Slatman
e2e9bf5494
Clarify some SCEP properties
1 year ago
Herman Slatman
c0a1837cd9
Verify full decrypter/signer configuration at usage time
...
When changing the SCEP configuration it is possible that one
or both of the decrypter configurations required are not available
or have been provided in a way that's not usable for actual SCEP
requests.
Instead of failing hard when provisioners are loaded,
which could result in the CA not starting properly, this type of
problematic configuration errors will now be handled at usage
time instead.
1 year ago
Herman Slatman
fc1fb51854
Improve SCEP authority initialization and reload
1 year ago
Herman Slatman
569a1be12c
Merge branch 'master' into herman/scep-provisioner-decrypter
1 year ago
Mariano Cano
cce7d9e839
Address comments from code review
1 year ago
Mariano Cano
c7c7decd5e
Add support for the disableSmallstepExtensions claim
...
This commit adds a new claim to exclude the Smallstep provisioner
extension from the generated certificates.
Fixes #620
1 year ago
Herman Slatman
1ce80cf740
Merge branch 'master' into herman/scep-provisioner-decrypter
1 year ago