-
Notifications
You must be signed in to change notification settings - Fork 4.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[1.9.x] ca: add support for an external trusted CA #12392
Merged
dnephin
merged 10 commits into
release/1.9.x
from
dnephin/backport-1.9-ca-external-root
Feb 22, 2022
Merged
[1.9.x] ca: add support for an external trusted CA #12392
dnephin
merged 10 commits into
release/1.9.x
from
dnephin/backport-1.9-ca-external-root
Feb 22, 2022
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…ermediate ca: add a test that uses an intermediate CA as the primary CA
The interface is documented as 'Sign will only return the leaf', and the other providers only return the leaf. It seems like this was added during the initial implementation, so is likely just something we missed. It doesn't break anything , but it does cause confusing cert chains in the API response which could break something in the future.
make TestNewCARoot much more strict compare the full result instead of only a few fields. add a test case with 2 and 3 certificates in the pem
And remove a no longer needed TODO
There's a chance this could flake if the secondary hasn't received the update yet, but running this test many times doesn't show any flakes yet.
dnephin
added
the
pr/no-changelog
PR does not need a corresponding .changelog entry
label
Feb 18, 2022
This pull request is being automatically deployed with Vercel (learn more). consul-ui-staging – ./ui🔍 Inspect: https://vercel.com/hashicorp/consul-ui-staging/87SSRkeuQ24qDFeENAtDTyUcWceU |
github-actions
bot
added
theme/connect
Anything related to Consul Connect, Service Mesh, Side Car Proxies
type/docs
Documentation needs to be created/updated/clarified
labels
Feb 18, 2022
rboyer
approved these changes
Feb 18, 2022
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
pr/no-changelog
PR does not need a corresponding .changelog entry
theme/connect
Anything related to Consul Connect, Service Mesh, Side Car Proxies
type/docs
Documentation needs to be created/updated/clarified
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Backport of #11783 and #11910
A few merge conflicts in import blocks, but not much else because I cherry-picked these commits from the 1.10.x backport (#12391).