Should grid-manager accept only "its" certificates? #3571

Open
opened 2020-12-21 05:09:05 +00:00 by meejah · 0 comments
Owner

When adding a grid-manager certificate to a Tahoe configuration with the "tahoe admin add-grid-manager-cert" command, the identify of the certificate is not checked.

It may be desirable to check if the public-key in the certificate matches the server's public-key. It probably makes sense to WARN only (as the operator may be getting ready to change their public key .. or for some other reason .. and could edit the config by hand anyway).

When adding a grid-manager certificate to a Tahoe configuration with the "tahoe admin add-grid-manager-cert" command, the identify of the certificate is not checked. It may be desirable to check if the public-key in the certificate matches the server's public-key. It probably makes sense to WARN only (as the operator may be getting ready to change their public key .. or for some other reason .. and could edit the config by hand anyway).
meejah added the
code-nodeadmin
normal
enhancement
n/a
labels 2020-12-21 05:09:05 +00:00
meejah added this to the undecided milestone 2020-12-21 05:09:05 +00:00
Sign in to join this conversation.
No Milestone
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Reference: tahoe-lafs/trac-2024-07-25#3571
No description provided.