Hi Hasitha,

We really appreciate your interest in Custos project. Please find the
inline comments.

On Tue, May 11, 2021 at 9:33 AM Hasitha Jayasundara <
[email protected]> wrote:

> Hi all,
>
> I'm Hasitha and I'm currently working as a Full Stack Engineer for a UK
> based tech company. I graduated from University Of Moratuwa Department of
> Electronic and Telecommunication Engineering Sri Lanka and completed a
> software engineering internship at a company called WSO2 which is an open
> source technology provider based in Sri Lanka. I also participated in
> Google Summer of Code 2017 and successfully completed a project for
> implementing an inbound endpoint and a connector for IBM-MQ.
>
> I'm enthusiastic about the airavata-custos project and would be extremely
> interested in contributing to the project. I've already followed the wiki
> page[1] and the tutorial presented at the Gateways 2020 Conference [2] and
> I think I have a clear understanding about how custos operates in the real
> world.
>
> As a starting point I selected the issue #152 [3] which is to implement a
> cert manager task using Custos. The idea is to automate the cert renewal
> process so that the client's won't need to manually do it by going through
> Let's Encrypt cert renewal process. The task (cron job) will be responsible
> for,
>
>    - Connecting to Let’s Encrypt APIs and create certificates, update
>    certificates
>    - Saving updated certificates into a given location and where the server
>    application can use it
>
> The overall process can be illustrated as follows.
>
>
>
>    - Custos Cert Renewer task (Cron Job) will be executed on periodic
>    configurable time period
>    - Task will communicate with Let's Encrypt using ACME(Automated
>    Certificate Management Environments) protocol. (I've already tested this
>    with acme4j [4] which is a java client for ACME protocol and it's
> working
>    fine without any issues)
>    - Task will then obtain the updated certificate and store it in a given
>    path in Custos (probably in a persistent volume)
>    - Client applications can query certificates from Custos and add them to
>    client trustore on demand to call a server application
>
> Following I listed out some of the concerns I'm having at the moment.
>
>    - In order to obtain an updated certificates,
>
>
>    1. we need to have an account in CA with a public and a private key
>    pair. Do we already have an account in Let's Encrypt for this type of
> work
>    or Is it possible to create a dedicated account for the cert renewer
> task?
>

yes, we can create a test account in Let's Encrypt.

   2. we need to provide CNs (domain names) for Let's Encrypt. Where do we
>    store the domain names of the clients?
>

I guess you are referring to the server application domains. those should
be configurable and can be stored in a configuration file.


>    - After obtaining the certificate, it's required to save it in Custos in
>    a given path. Do we already have an endpoint to achieve this?
>

Yes, Custos has a secret management service to save certificates.


>    - Client applications can query the certificates in Custos. How can we
>    provide the clients the information about the path to query?
>


Client applications can use Custos service accounts to access Custos APIs,


>
> Please have a look at the above and let me know your opinion.
>
> Regards
>
> [1].
>
> https://cwiki.apache.org/confluence/display/CUSTOS/Custos+Architecture+and+Internals
> [2]. https://youtu.be/CuBvFj194Kg
> [3]. https://github.com/apache/airavata-custos/issues/152
> [4]. https://github.com/shred/acme4j
>


-- 
Research Software Engineer
Indiana University, IN

Reply via email to