Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Forbid ssh key signing with specified extensions when role allowed_extensions is not set #12847

Merged
merged 3 commits into from Oct 15, 2021

Commits on Oct 15, 2021

  1. Forbid ssh key signing with specified extensions when role allowed_ex…

    …tensions is not set
    
     - This is a behaviour change on how we process the allowed_extensions role
       parameter when it does not contain a value. The previous handling allowed
       a client to override and specify any extension they requested.
     - We now require a role to explicitly set this behaviour by setting the parameter
       to a '*' value which matches the behaviour of other keys such as allowed_users
       within the role.
     - No migration of existing roles is provided either, so operators if they truly
       want this behaviour will need to update existing roles appropriately.
    stevendpclark committed Oct 15, 2021
    Configuration menu
    Copy the full SHA
    181e590 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    674e663 View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    0e974b2 View commit details
    Browse the repository at this point in the history