dependabot[bot]
4e077f997e
Bump cloud.google.com/go/security from 1.8.0 to 1.9.0
...
Bumps [cloud.google.com/go/security](https://github.com/googleapis/google-cloud-go ) from 1.8.0 to 1.9.0.
- [Release notes](https://github.com/googleapis/google-cloud-go/releases )
- [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/documentai/CHANGES.md )
- [Commits](https://github.com/googleapis/google-cloud-go/compare/asset/v1.8.0...asset/v1.9.0 )
---
updated-dependencies:
- dependency-name: cloud.google.com/go/security
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Mariano Cano
aed1738ad0
Upgrade pkcs7 to the latest patches branch
...
smallstep/pkcs7@patches includes now support for generic Decrypter
methods, so KMS can be used instead of a key in disk with SCIM
2 years ago
Max
c407354c70
Merge pull request #1137 from smallstep/dependabot/go_modules/google.golang.org/api-0.100.0
...
Bump google.golang.org/api from 0.99.0 to 0.100.0
2 years ago
dependabot[bot]
3e96113162
Bump github.com/stretchr/testify from 1.8.0 to 1.8.1
...
Bumps [github.com/stretchr/testify](https://github.com/stretchr/testify ) from 1.8.0 to 1.8.1.
- [Release notes](https://github.com/stretchr/testify/releases )
- [Commits](https://github.com/stretchr/testify/compare/v1.8.0...v1.8.1 )
---
updated-dependencies:
- dependency-name: github.com/stretchr/testify
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
016973fd2b
Bump google.golang.org/api from 0.99.0 to 0.100.0
...
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client ) from 0.99.0 to 0.100.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases )
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md )
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.99.0...v0.100.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/api
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
b83f268b4d
Bump google.golang.org/api from 0.98.0 to 0.99.0
...
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client ) from 0.98.0 to 0.99.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases )
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md )
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.98.0...v0.99.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/api
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
c3f6dcf7e7
Bump github.com/googleapis/gax-go/v2 from 2.5.1 to 2.6.0
...
Bumps [github.com/googleapis/gax-go/v2](https://github.com/googleapis/gax-go ) from 2.5.1 to 2.6.0.
- [Release notes](https://github.com/googleapis/gax-go/releases )
- [Commits](https://github.com/googleapis/gax-go/compare/v2.5.1...v2.6.0 )
---
updated-dependencies:
- dependency-name: github.com/googleapis/gax-go/v2
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Max
70828b882f
Merge pull request #1111 from smallstep/dependabot/go_modules/github.com/hashicorp/vault/api-1.8.1
...
Bump github.com/hashicorp/vault/api from 1.8.0 to 1.8.1
2 years ago
dependabot[bot]
9ee11fd850
Bump google.golang.org/grpc from 1.50.0 to 1.50.1
...
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go ) from 1.50.0 to 1.50.1.
- [Release notes](https://github.com/grpc/grpc-go/releases )
- [Commits](https://github.com/grpc/grpc-go/compare/v1.50.0...v1.50.1 )
---
updated-dependencies:
- dependency-name: google.golang.org/grpc
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
3676c59599
Bump github.com/hashicorp/vault/api from 1.8.0 to 1.8.1
...
Bumps [github.com/hashicorp/vault/api](https://github.com/hashicorp/vault ) from 1.8.0 to 1.8.1.
- [Release notes](https://github.com/hashicorp/vault/releases )
- [Changelog](https://github.com/hashicorp/vault/blob/main/CHANGELOG.md )
- [Commits](https://github.com/hashicorp/vault/compare/v1.8.0...v1.8.1 )
---
updated-dependencies:
- dependency-name: github.com/hashicorp/vault/api
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
max furman
7203739369
Fix err assert linter warnings - upgrade outdated package
2 years ago
Max
b142fc70f7
Merge pull request #1099 from smallstep/dependabot/go_modules/google.golang.org/grpc-1.50.0
...
Bump google.golang.org/grpc from 1.49.0 to 1.50.0
2 years ago
Max
32edc54946
Merge pull request #1100 from smallstep/dependabot/go_modules/github.com/sirupsen/logrus-1.9.0
...
Bump github.com/sirupsen/logrus from 1.8.1 to 1.9.0
2 years ago
dependabot[bot]
b27d36d556
Bump go.step.sm/crypto from 0.20.0 to 0.21.0
...
Bumps [go.step.sm/crypto](https://github.com/smallstep/crypto ) from 0.20.0 to 0.21.0.
- [Release notes](https://github.com/smallstep/crypto/releases )
- [Commits](https://github.com/smallstep/crypto/compare/v0.20.0...v0.21.0 )
---
updated-dependencies:
- dependency-name: go.step.sm/crypto
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
2522efe27a
Bump github.com/sirupsen/logrus from 1.8.1 to 1.9.0
...
Bumps [github.com/sirupsen/logrus](https://github.com/sirupsen/logrus ) from 1.8.1 to 1.9.0.
- [Release notes](https://github.com/sirupsen/logrus/releases )
- [Changelog](https://github.com/sirupsen/logrus/blob/master/CHANGELOG.md )
- [Commits](https://github.com/sirupsen/logrus/compare/v1.8.1...v1.9.0 )
---
updated-dependencies:
- dependency-name: github.com/sirupsen/logrus
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
2ee4218a69
Bump google.golang.org/grpc from 1.49.0 to 1.50.0
...
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go ) from 1.49.0 to 1.50.0.
- [Release notes](https://github.com/grpc/grpc-go/releases )
- [Commits](https://github.com/grpc/grpc-go/compare/v1.49.0...v1.50.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/grpc
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Herman Slatman
764b7bb02f
Update `github.com/smallstep/nosql` to v0.5.0
...
This version of `nosql` includes some fixes for MySQL DSNs. The
tag is backdated a bit, as to not include the most recent
changes, which may have a bigger impact.
Also ran `go mod tidy`, `go mod vendor`
2 years ago
Mariano Cano
bd1938b0da
Add support for storing or sending attestation data to linkedca
2 years ago
Max
a4f6b1ba0f
Merge pull request #1086 from smallstep/dependabot/go_modules/github.com/hashicorp/vault/api/auth/kubernetes-0.3.0
...
Bump github.com/hashicorp/vault/api/auth/kubernetes from 0.1.0 to 0.3.0
2 years ago
Max
87079a87d6
Merge pull request #1085 from smallstep/dependabot/go_modules/cloud.google.com/go/security-1.8.0
...
Bump cloud.google.com/go/security from 1.7.0 to 1.8.0
2 years ago
dependabot[bot]
3abb42dd1d
Bump github.com/hashicorp/vault/api/auth/kubernetes from 0.1.0 to 0.3.0
...
Bumps [github.com/hashicorp/vault/api/auth/kubernetes](https://github.com/hashicorp/vault ) from 0.1.0 to 0.3.0.
- [Release notes](https://github.com/hashicorp/vault/releases )
- [Changelog](https://github.com/hashicorp/vault/blob/main/CHANGELOG.md )
- [Commits](https://github.com/hashicorp/vault/compare/v0.1.0...v0.3.0 )
---
updated-dependencies:
- dependency-name: github.com/hashicorp/vault/api/auth/kubernetes
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
eba73d2aea
Bump github.com/newrelic/go-agent/v3 from 3.18.0 to 3.19.2
...
Bumps [github.com/newrelic/go-agent/v3](https://github.com/newrelic/go-agent ) from 3.18.0 to 3.19.2.
- [Release notes](https://github.com/newrelic/go-agent/releases )
- [Changelog](https://github.com/newrelic/go-agent/blob/master/CHANGELOG.md )
- [Commits](https://github.com/newrelic/go-agent/compare/v3.18.0...v3.19.2 )
---
updated-dependencies:
- dependency-name: github.com/newrelic/go-agent/v3
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Max
32feef3275
Merge pull request #1084 from smallstep/dependabot/go_modules/github.com/hashicorp/vault/api/auth/approle-0.3.0
...
Bump github.com/hashicorp/vault/api/auth/approle from 0.1.1 to 0.3.0
2 years ago
Max
f2628697db
Merge pull request #1082 from smallstep/dependabot/go_modules/github.com/rs/xid-1.4.0
...
Bump github.com/rs/xid from 1.2.1 to 1.4.0
2 years ago
Max
2ef5c98384
Merge pull request #1067 from smallstep/dependabot/go_modules/github.com/urfave/cli-1.22.10
...
Bump github.com/urfave/cli from 1.22.4 to 1.22.10
2 years ago
dependabot[bot]
5f0fa57844
Bump cloud.google.com/go/security from 1.7.0 to 1.8.0
...
Bumps [cloud.google.com/go/security](https://github.com/googleapis/google-cloud-go ) from 1.7.0 to 1.8.0.
- [Release notes](https://github.com/googleapis/google-cloud-go/releases )
- [Changelog](https://github.com/googleapis/google-cloud-go/blob/main/documentai/CHANGES.md )
- [Commits](https://github.com/googleapis/google-cloud-go/compare/asset/v1.7.0...redis/v1.8.0 )
---
updated-dependencies:
- dependency-name: cloud.google.com/go/security
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
211b1c01c0
Bump github.com/hashicorp/vault/api/auth/approle from 0.1.1 to 0.3.0
...
Bumps [github.com/hashicorp/vault/api/auth/approle](https://github.com/hashicorp/vault ) from 0.1.1 to 0.3.0.
- [Release notes](https://github.com/hashicorp/vault/releases )
- [Changelog](https://github.com/hashicorp/vault/blob/main/CHANGELOG.md )
- [Commits](https://github.com/hashicorp/vault/compare/v0.1.1...v0.3.0 )
---
updated-dependencies:
- dependency-name: github.com/hashicorp/vault/api/auth/approle
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
510122f026
Bump github.com/rs/xid from 1.2.1 to 1.4.0
...
Bumps [github.com/rs/xid](https://github.com/rs/xid ) from 1.2.1 to 1.4.0.
- [Release notes](https://github.com/rs/xid/releases )
- [Commits](https://github.com/rs/xid/compare/v1.2.1...v1.4.0 )
---
updated-dependencies:
- dependency-name: github.com/rs/xid
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Max
70abbdfc70
Merge pull request #1068 from smallstep/dependabot/go_modules/go.step.sm/cli-utils-0.7.5
...
Bump go.step.sm/cli-utils from 0.7.4 to 0.7.5
2 years ago
Max
8139179084
Merge pull request #1069 from smallstep/dependabot/go_modules/github.com/google/go-cmp-0.5.9
...
Bump github.com/google/go-cmp from 0.5.8 to 0.5.9
2 years ago
Max
af4183df18
Merge pull request #1077 from smallstep/dependabot/go_modules/google.golang.org/api-0.98.0
...
Bump google.golang.org/api from 0.96.0 to 0.98.0
2 years ago
Max
e5c5b0cb49
Merge pull request #1070 from smallstep/dependabot/go_modules/github.com/slackhq/nebula-1.6.1
...
Bump github.com/slackhq/nebula from 1.5.2 to 1.6.1
2 years ago
dependabot[bot]
ef75d4f3c6
Bump go.step.sm/cli-utils from 0.7.4 to 0.7.5
...
Bumps [go.step.sm/cli-utils](https://github.com/smallstep/cli-utils ) from 0.7.4 to 0.7.5.
- [Release notes](https://github.com/smallstep/cli-utils/releases )
- [Commits](https://github.com/smallstep/cli-utils/compare/v0.7.4...v0.7.5 )
---
updated-dependencies:
- dependency-name: go.step.sm/cli-utils
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
3faa8717b3
Bump google.golang.org/api from 0.96.0 to 0.98.0
...
Bumps [google.golang.org/api](https://github.com/googleapis/google-api-go-client ) from 0.96.0 to 0.98.0.
- [Release notes](https://github.com/googleapis/google-api-go-client/releases )
- [Changelog](https://github.com/googleapis/google-api-go-client/blob/main/CHANGES.md )
- [Commits](https://github.com/googleapis/google-api-go-client/compare/v0.96.0...v0.98.0 )
---
updated-dependencies:
- dependency-name: google.golang.org/api
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
0027f93fb9
Bump github.com/google/go-cmp from 0.5.8 to 0.5.9
...
Bumps [github.com/google/go-cmp](https://github.com/google/go-cmp ) from 0.5.8 to 0.5.9.
- [Release notes](https://github.com/google/go-cmp/releases )
- [Commits](https://github.com/google/go-cmp/compare/v0.5.8...v0.5.9 )
---
updated-dependencies:
- dependency-name: github.com/google/go-cmp
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Andrew Reed
7101fbb0ee
Provisioner webhooks ( #1001 )
2 years ago
dependabot[bot]
132b32b5a5
Bump github.com/urfave/cli from 1.22.4 to 1.22.10
...
Bumps [github.com/urfave/cli](https://github.com/urfave/cli ) from 1.22.4 to 1.22.10.
- [Release notes](https://github.com/urfave/cli/releases )
- [Changelog](https://github.com/urfave/cli/blob/main/docs/CHANGELOG.md )
- [Commits](https://github.com/urfave/cli/compare/v1.22.4...v1.22.10 )
---
updated-dependencies:
- dependency-name: github.com/urfave/cli
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
dependabot[bot]
7420172d63
Bump github.com/slackhq/nebula from 1.5.2 to 1.6.1
...
Bumps [github.com/slackhq/nebula](https://github.com/slackhq/nebula ) from 1.5.2 to 1.6.1.
- [Release notes](https://github.com/slackhq/nebula/releases )
- [Changelog](https://github.com/slackhq/nebula/blob/master/CHANGELOG.md )
- [Commits](https://github.com/slackhq/nebula/compare/v1.5.2...v1.6.1 )
---
updated-dependencies:
- dependency-name: github.com/slackhq/nebula
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2 years ago
Mariano Cano
906c5067b9
Include attestation roots on provisioner converters
2 years ago
Herman Slatman
a8125846dd
Add TPM attestation
2 years ago
max furman
1e0ea6f958
more linting fixes
2 years ago
Mariano Cano
191d9e8629
Use go.step.sm/crypto to set the permanent identifier
2 years ago
Brandon Weeks
de5b0ef5c2
Verify key authorization is contained within the TPM quote extraData field
2 years ago
Brandon Weeks
248da10f32
Implement TPM attestation statement verification
2 years ago
Brandon Weeks
6f2b4d3042
Add ACME permanent-identifier identifier type
2 years ago
Mariano Cano
746ee2b6db
Upgrade go.step.sm/cli-utils
...
Fixes issue with step path
2 years ago
Mariano Cano
a795f4281c
Upgrade to go.step.sm/crypto v0.18.0
2 years ago
Herman Slatman
25cbe02b9e
Add provisioner template validation
...
Fixes #1012
2 years ago
Mariano Cano
df975122a0
Upgrade linkedca and add entry to changelog
2 years ago
Mariano Cano
bb0210e875
Fix typo in linkedca variable
2 years ago
Mariano Cano
66407139e5
Add methods to convert attestation formats
2 years ago
Mariano Cano
a2749ca8ed
Merge branch 'master' into device-attestation
2 years ago
Mariano Cano
45af68b244
Upgrade go.step.sm/crypto
2 years ago
Mariano Cano
6db631df51
Upgrade go.step.sm/crypto@attest
2 years ago
Mariano Cano
a893d6e7f7
Upgrade go.step.sm/cli-utils
...
Fixes issue with step path
2 years ago
Mariano Cano
1938b1bb34
Merge branch 'master' into herman/fix-template-validation
2 years ago
Mariano Cano
1d1e024b84
Upgrade to go.step.sm/crypto v0.18.0
2 years ago
Mariano Cano
2a44972830
Run go mod tidy
2 years ago
Mariano Cano
bca311b05e
Add acme property to enable challenges
...
Fixes #1027
2 years ago
Herman Slatman
6b7b989988
Add provisioner template validation
...
Fixes #1012
2 years ago
Mariano Cano
693dc39481
Merge branch 'master' into device-attestation
2 years ago
Mariano Cano
6cab4d328e
Add a middleware to automatically route HEAD requests to GET
...
Fixes #992
2 years ago
Mariano Cano
0c7467ceb2
Allow to automatically configure and linked RA
2 years ago
Mariano Cano
5df1694250
Add endpoint id for the RA certificate
...
In a linked RA mode, send an endpoint id to group the server
certificates.
2 years ago
Mariano Cano
2f7cb9225f
Use go.step.sm/crypto to set the permanent identifier
2 years ago
Mariano Cano
369b8f81c3
Use go.step.sm/crypto/kms
...
Fixes #975
2 years ago
Mariano Cano
e02a190fa7
Merge branch 'master' into device-attestation
2 years ago
Mariano Cano
8445c29db6
Change actions to build using Go 1.19
...
Fixes #998
2 years ago
Mariano Cano
38fb92452f
Merge pull request #993 from smallstep/ra-ids
...
RA provisioner IDs
2 years ago
Mariano Cano
821743f71e
Upgrade newrelic to v3
2 years ago
Aaron Bieber
135c481893
Update deps to bring in support for OpenBSD
...
OpenBSD support was added to the following deps:
- github.com/go-piv/piv-go in https://github.com/go-piv/piv-go/pull/101
- github.com/newrelic/go-agent in https://github.com/newrelic/go-agent/pull/455
- github.com/miekg/pkcs11 in https://github.com/miekg/pkcs11/pull/140
With these deps bumped, tests all pass on OpenBSD amd64.
2 years ago
Mariano Cano
a2f7766943
Use released version of linkedca
2 years ago
Mariano Cano
64744562c6
Send RA provisioner to linkedca.
2 years ago
Brandon Weeks
77c6d10fd6
Verify key authorization is contained within the TPM quote extraData field
2 years ago
Brandon Weeks
e1ec31c0ed
Implement TPM attestation statement verification
2 years ago
Brandon Weeks
2ac8b69da2
Add ACME permanent-identifier identifier type
2 years ago
Mariano Cano
2adf8caac7
Fix Dependabot warning on an indirect dependency
2 years ago
Erik De Lamarter
dec1067add
vault kubernetes auth
2 years ago
Herman Slatman
d1ab1d5431
Merge branch 'master' into herman/update-crypto-0.16.2
2 years ago
Herman Slatman
b75ce3acbd
Update to go.step.sm/crypto v0.16.2
...
This patch release of go.step.sm/crypto fixes an issue with
not all `Subject` names being available for usage in a template
as `ExtraNames`.
2 years ago
Herman Slatman
7030dbb7a1
Use github.com/smallstep/pkcs7 fork with patches applied
2 years ago
Herman Slatman
ed231d29e2
Update to go.step.sm/linkedca@v0.16.1
2 years ago
Herman Slatman
f0272dc717
Fix import replacement of linkedca
2 years ago
Herman Slatman
60d8b22d89
Change context retrievers to MustTFromContext
2 years ago
Herman Slatman
ad2de16299
Merge branch 'master' into herman/allow-deny
3 years ago
Mariano Cano
fe9c3cf753
Merge branch 'master' into ahmet2mir-feat/vault
3 years ago
Herman Slatman
d6be9450be
Merge branch 'master' into herman/allow-deny
3 years ago
Mariano Cano
674dc3c844
Rename unreleased claim to allowRenewalAfterExpiry for consistency.
3 years ago
Mariano Cano
9134bad22c
Run go mod tidy.
3 years ago
Mariano Cano
37b521ec6c
Merge branch 'master' into feat/vault
3 years ago
Herman Slatman
9797b3350e
Merge branch 'master' into herman/allow-deny
3 years ago
Mariano Cano
d4013f0df6
Update linkedca
3 years ago
Herman Slatman
7df52dbb76
Add ACME EAB policy
3 years ago
Herman Slatman
235a2c9d04
Pin to specific version of go.step.sm/linkedca
3 years ago
Herman Slatman
5daa9fc0b1
Merge branch 'master' into herman/allow-deny
3 years ago
Mariano Cano
f5bf46b950
Upgrade go.step.sm/crypto
3 years ago
Herman Slatman
2fbdf7d5b0
Merge branch 'master' into herman/allow-deny
3 years ago
Herman Slatman
1dbaa62740
Update cloud.google.com/go/kms
3 years ago
Herman Slatman
dc23fd23bf
Merge branch 'master' into herman/allow-deny-next
3 years ago
Herman Slatman
6b620c8e9c
Improve protobuf unmarshaling error handling
3 years ago
Herman Slatman
81b0c6c37c
Add API implementation for authority and provisioner policy
3 years ago
Mariano Cano
c903f00cd4
Rename claim to allowRenewAfterExpiry.
3 years ago
Mariano Cano
616490a9c6
Refactor renew after expiry token authorization
...
This changes adds a new authority method that authorizes the
renew after expiry tokens.
3 years ago
Mariano Cano
3fb5e57f12
Upgrade nosql package
...
The new version of the package allows filtering out database drivers
using Go tags.
3 years ago
Mariano Cano
6f46cdb432
Merge pull request #829 from vijayjt/new-azure-token-authz-options
...
Add subscription and object ID validation options to Azure provisioner
3 years ago
vijayjt
7a32c312bf
Update linkedca dependency version
3 years ago
max furman
9d885e6914
bump nosql for postgres support
3 years ago
Mariano Cano
c0525381eb
Merge branch 'master' into feat/vault
3 years ago
Ahmet DEMIR
ab5197500c
fix: a certificat must excldue the root and you should use verified chained intermediate
3 years ago
Herman Slatman
c7c5c3c94e
Merge branch 'master' into herman/scep-macos-renewal-fixes
3 years ago
Mariano Cano
09a9b3e1c8
Upgrade go.step.sm/crypto
3 years ago
Herman Slatman
3b72d241e0
Add LinkedCA integration for improved SCEP provisioner
3 years ago
Ahmet DEMIR
d957a57e24
fix: apply mariano suggestions and fixes
...
* use json.RawMessage to remote mapstructure in options
* use vault secretid structure to support multiple source aka string, file and env
* remove log prefix
* return raw cert on error on newline for cert and csr
* clean sans, commonName in createCertificate (bad copy/paste from StepCAS)
* verify authority fingerprint
* convert serial on revoke to bigint, bytes and vault dashed representation
3 years ago
Ahmet DEMIR
16390694e1
feat(vault): adding hashicorp vault cas
3 years ago
Mariano Cano
01a76445ea
Upgrade go.step.sm/crypto
3 years ago
Mariano Cano
98044cf08d
Use a tagged version of linkedca
3 years ago
Mariano Cano
6a1d0cb9f8
Add linkedca conversions.
3 years ago
Mariano Cano
9ec0276887
Update certificate set with new api.
3 years ago
Mariano Cano
32390a2964
Add initial implementation of a nebula provisioner.
...
A nebula provisioner will generate a X509 or SSH certificate with
the identities in the nebula certificate embedded in the token.
The token is signed with the private key of the nebula certificate.
3 years ago
max furman
7fac8c96c3
Merge branch 'master' into max/context
3 years ago
max furman
196f6b45c9
bump cli-utils to 0.7.0
3 years ago
max furman
b5bf79b84e
bump nosql library
3 years ago
max furman
555431448c
bump version ofcli-utils
3 years ago
Herman Slatman
2c05f488f6
Remove support for Go 1.15
3 years ago
Mariano Cano
62a20c7db5
Upgrade cli-utils with latest version of promptui
3 years ago
Mariano Cano
9958e0645f
Replace promptui with apache-compatible fork.
...
Promptui depends on github.com/juju/ansiterm that is licensed under
LGPL. The fork replaces ansiterm.TabWriter with the one in the
standard library.
3 years ago
Mariano Cano
0927e0d22a
Upgrade go.step.sm/crypto dependency
...
The new version removes "env" and "expandenv" sprig functions.
3 years ago
Mariano Cano
e15b5faf7d
Merge branch 'master' into keyvault
3 years ago
Mariano Cano
d8720c3723
Update linkedca package.
3 years ago
Mariano Cano
48549bf317
Initialize windows terminal on all binaries.
3 years ago
Mariano Cano
6389100325
Add unit tests for azurekms.
3 years ago
Mariano Cano
392a18465f
Add initial implementation of Azure Key Vault KMS.
...
Fixes #462
3 years ago
Mariano Cano
ad82d8a250
Upgrade go.step.sm/crypto as long with go-jose.v2
...
There was a typo in the OKP template causing bad fingerprints for
Ed25519 keys.
See a10ff54e00
Fixes #705
3 years ago
max furman
8df9f629b1
go mod tidy
3 years ago
Herman Slatman
73d0a11a20
Update github.com/micromdm/scep/v2
3 years ago
Herman Slatman
611859eec4
Update go.mozilla.org/pkcs7
...
This includes the fix as described in https://github.com/mozilla-services/pkcs7/pull/59 ,
which was the reason a fork of the library was used.
3 years ago
Mariano Cano
9e7a3cd897
Update go.step.sm/crypto
3 years ago
Mariano Cano
352acf8faa
Upgrade golang.org/x/crypto
3 years ago
Mariano Cano
2c5080aae0
go mod tidy
3 years ago
Mariano Cano
42fde8ba28
Merge branch 'master' into linkedca
3 years ago
max furman
2317bf183b
Nosql and badger bump
3 years ago
max furman
cc9bc9c84b
Bump Badger
3 years ago
max furman
f53f78974e
Badger bump to fix issue with caddy build
3 years ago
Mariano Cano
456ffd8806
Use linkedca v0.5.0
3 years ago
Mariano Cano
28e882c9b3
Add deployment type to export.
3 years ago
Mariano Cano
798b90c359
Move linkedca configuration to the main package.
3 years ago
Mariano Cano
de292fbed6
Use branch version of linkedca.
3 years ago
Mariano Cano
d0c1530f89
Remove replace of linkedca package.
3 years ago
Mariano Cano
17eef81c91
Remove linkerd replace.
3 years ago
Mariano Cano
a72eab915b
Use linkedca v0.1.0
3 years ago
Mariano Cano
f7e09af9df
Implement the login command.
...
The login commands creates a new certificate for the linked ca.
This certificate will be used to sync data with the linkedca
endpoint.
3 years ago
max furman
77fdfc9fa3
Merge branch 'master' into max/cert-mgr-crud
3 years ago
max furman
9fdef64709
Admin level API for provisioner mgmt v1
3 years ago
Mariano Cano
65dacc2795
Replace golint with revive
3 years ago
Mariano Cano
2a97389f1b
Upgrade dependencies.
3 years ago
Mariano Cano
072bd0dcf4
Add support for Google CAS v1
3 years ago
Herman Slatman
66a67ed691
Update to v2.0.0 of github.com/micromdm/scep
3 years ago
Herman Slatman
75cd3ab0ac
Change to a fixed fork of go.mozilla.org/pkcs7
...
Hopefully this will be a temporary change until
the fix is merged in the upstream module.
3 years ago
Herman Slatman
2a249d20de
Refactor initialization of SCEP authority
3 years ago
Herman Slatman
48c86716a0
Add rudimentary (and incomplete) support for SCEP
3 years ago
Herman Slatman
bc2bb53009
Merge branch 'master' into hs/scep
3 years ago
Mariano Cano
f84c8f846a
Upgrade x/crypto
...
Although this does not affects us the old version had the vulnerability
CVE-2020-29652
3 years ago
max furman
b205f50412
bump crypto to 0.8.3 and go mod tidy
3 years ago
Herman Slatman
c3d9cef497
Update to v2.0.0 of github.com/micromdm/scep
4 years ago
Herman Slatman
c5e4ea08b3
Merge branch 'master' into hs/scep
4 years ago
Herman Slatman
a526065d0c
Merge branch 'master' into hs/scep
4 years ago
Mariano Cano
561341a6f2
Update go.step.sm/crypto.
4 years ago
max furman
6861202762
go.sum update
4 years ago
Herman Slatman
efd5501aca
Merge branch 'master' into hs/scep
4 years ago
Mariano Cano
d74f1fa55e
Use cli-utils v0.2.0
4 years ago
Mariano Cano
a1a7e38a49
Add support for cli-utils with powershell support.
4 years ago
Herman Slatman
9df5f513e7
Change to a fixed fork of go.mozilla.org/pkcs7
...
Hopefully this will be a temporary change until
the fix is merged in the upstream module.
4 years ago
Herman Slatman
7948f65ac0
Merge branch 'master' into hs/scep
4 years ago
Herman Slatman
7ad90d10b3
Refactor initialization of SCEP authority
4 years ago
max furman
8b4bbd3d39
go mod tidy
4 years ago
Herman Slatman
9e43dc85d8
Merge branch 'master' into hs/scep-master
4 years ago
Herman Slatman
ffdd58ea3c
Add rudimentary (and incomplete) support for SCEP
4 years ago
Mariano Cano
f289d1ee1f
Update to crypto11 v1.2.4
...
This version now includes my changes to delete a certificate.
4 years ago
Mariano Cano
4fbf7569fa
Merge branch 'master' into pkcs11
4 years ago
Mariano Cano
1d47a7284d
Upgrade nosql with a version of badger compatible with 32bits
4 years ago
Mariano Cano
6c0cf99b24
Upgrade nosql with a 32-bit version of badger.
4 years ago
Mariano Cano
8dca652bc7
Add support for PKCS #11 KMS.
...
The implementation works with YubiHSM2. Unit tests are still pending.
Fixes #301
4 years ago
Mariano Cano
c61222de1d
Upgrade nosql version.
...
nosql has newer version of badgers v1 and v2.
4 years ago
Mariano Cano
71a8e87eec
Update go.sum with new version of go-piv.
4 years ago
Mariano Cano
86c947babc
Upgrade crypto and fix test.
4 years ago
Mariano Cano
d6ea8b13ab
Upgrade crypto.
...
Related to #435
4 years ago
Mariano Cano
1feb4fcb26
Merge branch 'glance--sshagentkms'
4 years ago
Mariano Cano
ccc403cf89
Fix comments, and return an error instead of fatal.
4 years ago
Mariano Cano
7d9997618f
Upgrade crypto to v0.7.1
...
Add basic constraints extensions if defined.
4 years ago
Mariano Cano
2c164f39cc
Fix rebase.
4 years ago
Mariano Cano
a01c3defc0
Complete CloudCAS tests.
...
Upgrade cloud.google.com/go
4 years ago
Mariano Cano
2611fc04d4
Add initial tests for CreateCertificateAuthority.
4 years ago
Mariano Cano
fe7db340b0
Update go.step.sm/crypto dependency.
4 years ago
Mariano Cano
5deca85b14
Add initial support for `step ca init` with cloud cas.
...
Fixes smallstep/cli#363
4 years ago
Mariano Cano
921de7e07f
Upgrade crypto to v0.7.1
...
Add basic constraints extensions if defined.
4 years ago
Mariano Cano
736a6fb64e
Fix rebase.
4 years ago
Mariano Cano
b275758018
Complete CloudCAS tests.
...
Upgrade cloud.google.com/go
4 years ago
Mariano Cano
b2ae112dd2
Add initial tests for CreateCertificateAuthority.
4 years ago
Mariano Cano
461735718d
Update go.step.sm/crypto dependency.
4 years ago
Mariano Cano
2b4b902975
Add initial support for `step ca init` with cloud cas.
...
Fixes smallstep/cli#363
4 years ago
Mariano Cano
b79701202b
Use cli-utils@v0.1.0
4 years ago
Mariano Cano
40d0596b71
Use smallstep/cli-utils instead of smallstep/cli
4 years ago
max furman
81a0df9e45
go mod tidy
4 years ago
max furman
3f4d041082
bump cli to master
4 years ago
Mariano Cano
647b9b4541
Merge pull request #367 from smallstep/cas
...
Support for CAS Interface and CloudCAS
4 years ago
Mariano Cano
4c8bf87dc1
Use new admin template for K8ssa and admin-OIDC provisioners.
...
This change replaces the .Insecure.CR template to one that sets
all the SANs, but uses key usages and extended key usages for
regular TLS certificates.
4 years ago
Mariano Cano
a332c40530
Merge branch 'master' into cas
4 years ago
Mariano Cano
87bbcee239
Update go.sum
4 years ago
Mariano Cano
c8d9cb0a1d
Complete cloudcas using CAS v1beta1.
4 years ago
Mariano Cano
1b1f73dec6
Early attempt to develop a CAS interface.
4 years ago
Mariano Cano
3ac0ef2eaa
Update crypto to v0.6.0
4 years ago
Mariano Cano
f3b65e54ac
Update go.step.sm to v0.5.0
...
Solves the problem of enforcing the signature algorithm. This
causes issues if the intermediate key is not an ECDSA key.
4 years ago
Mariano Cano
8ee246edda
Upgrade go.step.sm to v0.4.0
4 years ago
Mariano Cano
ef86bedb2c
Upgrade go.step.sm dependency to v0.3.0
4 years ago
Mariano Cano
c94a1c51be
Merge branch 'master' into ssh-cert-templates
4 years ago
Mariano Cano
ba918100d0
Use go.step.sm/crypto/jose
...
Replace use of github.com/smallstep/cli/crypto with the new package
go.step.sm/crypto/jose.
4 years ago
Mariano Cano
03d642e59c
Update go.step.sm/crypto to v0.2.0
...
Fixes #302
4 years ago
max furman
cb594ed2e0
go mod tidy and golang 1.15.0 cleanup ...
...
- cs.NegotiatedProtocolIsMutual has been deprecated but we still build
in travis with 1.14 so for now we'll ignore this linting error
- string(int) was resolving to string of a single rune rather than
string of digits -> use fmt.Sprint
4 years ago
Mariano Cano
32ba80f446
Use pemutil branch.
4 years ago
Mariano Cano
d30a95236d
Use always go.step.sm/crypto
4 years ago
Mariano Cano
aaaa7e9b4e
Merge branch 'master' into cert-templates
4 years ago
Mariano Cano
533ad0ca20
Use always go.step.sm/crypto/x509util
4 years ago
Mariano Cano
e83e47a91e
Use sshutil and randutil from go.step.sm/crypto.
4 years ago
Mariano Cano
c8d225a763
Use x509util from go.step.sm/crypto/x509util
4 years ago
max furman
3f844c5e23
Update the way SubjectKeyId is calculated, and more ...
...
- swith lint to first in line for `make all`
- update tests to conform with new subjectkeyid
4 years ago
David Cowden
dc39eef721
aws: test badIDMS functional path
...
The existing test only covers the constructor logic. Also test the live
code path that is executed when a bad IDMS version is supplied.
4 years ago
Mariano Cano
978ad7e2b6
Fix merged tests.
4 years ago
Mariano Cano
0de15b0a42
Update cli dependency to master.
4 years ago
Mariano Cano
6736ddee69
Use smallstep/cli v0.14.6
4 years ago
max furman
e1fdd9300c
go mod tidy
4 years ago
max furman
b200e84967
Pull most recent cli and go mod tidy
4 years ago
max furman
1951669e13
wip
4 years ago
Mariano Cano
c32abb76cd
Add initial implementation to support AWS KMS.
4 years ago
Mariano Cano
6868190fff
Add initial support for yubikey.
5 years ago
max furman
c1a84c1405
go mod tidy
5 years ago
max furman
30e38dc501
Bumpt the version of cli for a certificates RC.
5 years ago
Mariano Cano
df3b9f637e
Use a tagged version of nosql.
5 years ago
max furman
3be95a82d0
Update version of nosql.
5 years ago
max furman
0573c00bd3
Simultaneous support for Badger V1+V2 and ...
...
* valueLogLoadingMode config for low RAM badger environments
5 years ago
max furman
fc50523779
go mod tidy
5 years ago
max furman
e03ce33cd9
go mod tidy and verify
5 years ago
max furman
17097eb9f0
Bump cli to v0.14.1 to break dependency cycle.
5 years ago
max furman
344e7b99fb
bump cli dependency
5 years ago
Mariano Cano
3480ed44c7
Upgrade github.com/x/crypto to fix a vulnerability in ssh.
...
* CVE-2020-9283
5 years ago
Mariano Cano
f868e07a76
Allow to use custom principals on cloud provisioners.
...
Fixes #203
5 years ago
Mariano Cano
21bd339b86
Merge branch 'master' into kms
5 years ago
Mariano Cano
752bfeeccd
Update cli dependency.
5 years ago
Mariano Cano
cbf1053255
Merge branch 'master' into kms
5 years ago
max furman
c66b183783
Update cli dep
5 years ago
Mariano Cano
3fb42935b4
Update cli dependency
5 years ago
Mariano Cano
549291c2ca
Upgrade smallste/cli
5 years ago
Mariano Cano
9d5b7e65e4
Upgrade golangci-lint to v1.22.2
5 years ago
Mariano Cano
895d3054a3
Remove the use of custom x509 package.
...
Upgrade cli dependency.
5 years ago
Mariano Cano
8297e5c717
Add tests for backdate and sshDefaultDuration
5 years ago
Mariano Cano
53334ce1e0
Update assert package.
5 years ago
Mariano Cano
e6cafb89b6
Update cli dependency.
5 years ago
max furman
ed7ef7229f
cli dep update
5 years ago
max furman
b9f6aacb0f
Move api errors to their own package and modify the typedef
5 years ago
Mariano Cano
79b408dcf7
Update dependencies.
5 years ago
Mariano Cano
3029addbf6
Use new version of nosql.
5 years ago
max furman
93320fd977
update cli dep
5 years ago
Mariano Cano
9c3349e90c
Go mod tidy.
5 years ago
Mariano Cano
e29892e9eb
Update cli dependency.
5 years ago
Mariano Cano
000885dea7
Move Option type to a new file.
5 years ago
max furman
c04f1e1bd4
sshpop first pass
5 years ago
Mariano Cano
ded8087042
Go mod tidy.
5 years ago
Mariano Cano
8e794259eb
Update dependencies.
5 years ago
Mariano Cano
b8817ad648
Add proxycommand and new lines to templates.
5 years ago
Mariano Cano
ec90c41de6
Use nosql version with go mod.
5 years ago
Mariano Cano
d59a07ad89
Upgrade cli version.
5 years ago
Mariano Cano
bceb12a169
Upgrade go-jose to 2.4.0.
5 years ago
Mariano Cano
6489c26d4c
Use github.com/Masterminds/sprig/v3
5 years ago
Mariano Cano
69a1b68283
Merge branch 'ssh' into kms
5 years ago
Mariano Cano
ec2046bba8
Add grpc dependency.
5 years ago
Mariano Cano
e98d7832b9
Add options to read the roots and federated roots from a bundle.
5 years ago
Mariano Cano
44eccc6bd8
Merge branch 'ssh' into kms
5 years ago
Mariano Cano
3ce267cdd6
Upgrade smallste/cli
5 years ago
Mariano Cano
3cbf30b555
Upgrade golangci-lint to v1.22.2
5 years ago
Mariano Cano
085ae82163
Remove the use of custom x509 package.
...
Upgrade cli dependency.
5 years ago
Mariano Cano
995375013d
Update dependencies for kms support.
5 years ago
Mariano Cano
165a91858e
Add tests for backdate and sshDefaultDuration
5 years ago
Mariano Cano
50717b3ffa
Update assert package.
5 years ago
Mariano Cano
1fa35491ea
Update cli dependency.
5 years ago
max furman
6200aeaad0
cli dep update
5 years ago
max furman
f9ef5070f9
Move api errors to their own package and modify the typedef
5 years ago
Mariano Cano
ba11f6acb7
Update dependencies.
5 years ago
Mariano Cano
d210082113
Use new version of nosql.
5 years ago
max furman
623be4ef09
update cli dep
5 years ago
Mariano Cano
014d2c7ccd
Go mod tidy.
5 years ago
Mariano Cano
f99d1007bc
Update cli dependency.
5 years ago
Mariano Cano
43b663e0c3
Move Option type to a new file.
5 years ago
max furman
b5f15531d8
sshpop first pass
5 years ago
Mariano Cano
5092e8cfc2
Go mod tidy.
5 years ago
Mariano Cano
45d94fa4bd
Update dependencies.
5 years ago
Mariano Cano
605d39e4e8
Add proxycommand and new lines to templates.
5 years ago
Mariano Cano
ba9eb47818
Use nosql version with go mod.
5 years ago
Mariano Cano
af64bf8d96
Upgrade cli version.
5 years ago
Mariano Cano
e8ad06ef35
Upgrade go-jose to 2.4.0.
5 years ago
Mariano Cano
f47516a15d
Use github.com/Masterminds/sprig/v3
5 years ago
Mariano Cano
edac867cf6
Update dependencies.
5 years ago
Mariano Cano
5cdb8f63b2
Add ignored files go.mod and go.sum
5 years ago