Hi all,

I'm Hasitha and I'm currently working as a Full Stack Engineer for a UK
based tech company. I graduated from University Of Moratuwa Department of
Electronic and Telecommunication Engineering Sri Lanka and completed a
software engineering internship at a company called WSO2 which is an open
source technology provider based in Sri Lanka. I also participated in
Google Summer of Code 2017 and successfully completed a project for
implementing an inbound endpoint and a connector for IBM-MQ.

I'm enthusiastic about the airavata-custos project and would be extremely
interested in contributing to the project. I've already followed the wiki
page[1] and the tutorial presented at the Gateways 2020 Conference [2] and
I think I have a clear understanding about how custos operates in the real
world.

As a starting point I selected the issue #152 [3] which is to implement a
cert manager task using Custos. The idea is to automate the cert renewal
process so that the client's won't need to manually do it by going through
Let's Encrypt cert renewal process. The task (cron job) will be responsible
for,

   - Connecting to Let’s Encrypt APIs and create certificates, update
   certificates
   - Saving updated certificates into a given location and where the server
   application can use it

The overall process can be illustrated as follows.



   - Custos Cert Renewer task (Cron Job) will be executed on periodic
   configurable time period
   - Task will communicate with Let's Encrypt using ACME(Automated
   Certificate Management Environments) protocol. (I've already tested this
   with acme4j [4] which is a java client for ACME protocol and it's working
   fine without any issues)
   - Task will then obtain the updated certificate and store it in a given
   path in Custos (probably in a persistent volume)
   - Client applications can query certificates from Custos and add them to
   client trustore on demand to call a server application

Following I listed out some of the concerns I'm having at the moment.

   - In order to obtain an updated certificates,


   1. we need to have an account in CA with a public and a private key
   pair. Do we already have an account in Let's Encrypt for this type of work
   or Is it possible to create a dedicated account for the cert renewer task?
   2. we need to provide CNs (domain names) for Let's Encrypt. Where do we
   store the domain names of the clients?


   - After obtaining the certificate, it's required to save it in Custos in
   a given path. Do we already have an endpoint to achieve this?
   - Client applications can query the certificates in Custos. How can we
   provide the clients the information about the path to query?

Please have a look at the above and let me know your opinion.

Regards

[1].
https://cwiki.apache.org/confluence/display/CUSTOS/Custos+Architecture+and+Internals
[2]. https://youtu.be/CuBvFj194Kg
[3]. https://github.com/apache/airavata-custos/issues/152
[4]. https://github.com/shred/acme4j

Reply via email to