Hi Isuru, Thanks for the explanation. I think I have a clear idea on how to proceed with the Let's Encrypt part of the implementation now.
I already started the implementation and am currently designing a solution for handling the Let's Encrypt challenge. Once that is done I am thinking of starting the certificates store process in Custos. I think I'll probably need some setup completed first for making authenticated requests to Custos. Found an issue with the certificate store path in the current implementation and I've sent a fix for that. [1] Regards [1]. https://github.com/apache/airavata-custos/pull/160 On Thu, May 13, 2021 at 9:31 AM Isuru Ranawaka <[email protected]> wrote: > Hi Hasitha, > > Glad to hear that you have gone through the code. Please feel free to > submit bug fixes as you see. > > We use HarshiCorp vault to store secrets. The paths you mentioned are > actually created in the vault. Precisely, owner_id is the id of the user or > the service account that owns the certificate. Token is an identifier that > can be used to retrieve the certificate later. > > thanks > Isuru > > On Wed, May 12, 2021 at 11:08 PM Hasitha Jayasundara < > [email protected]> wrote: > > > Hi Isuru, > > > > Thanks for the reply. Based on your comment that custos already has an > > endpoint to store certificates I took some time to go through the Secret > > Management Service and the proto for Resource Secret Service. > > > > According to my observation, I think I can use *POST - > > /resource-secret-management/v1.0.0/secret/certificate* endpoint to do > > certificate uploading. (Correct me if I'm wrong) > > > > Going through the code I found that certificate is stored in > > */resourcesecret/<tenant_id>/<owner_id>/ssh/<token>*. The <tenant_id>, > > <owner_id> and <token> are received through the request body. I am not > 100% > > clear about <owner_id> and <token> fields in the context of custos secret > > manager service. Could you please explain a bit about <owner_id> and the > > <token>? > > > > Regards > > > > On Wed, May 12, 2021 at 7:30 AM Isuru Ranawaka <[email protected]> > wrote: > > > > > Hi Hasitha, > > > > > > We really appreciate your interest in Custos project. Please find the > > > inline comments. > > > > > > On Tue, May 11, 2021 at 9:33 AM Hasitha Jayasundara < > > > [email protected]> wrote: > > > > > > > Hi all, > > > > > > > > I'm Hasitha and I'm currently working as a Full Stack Engineer for a > UK > > > > based tech company. I graduated from University Of Moratuwa > Department > > of > > > > Electronic and Telecommunication Engineering Sri Lanka and completed > a > > > > software engineering internship at a company called WSO2 which is an > > open > > > > source technology provider based in Sri Lanka. I also participated in > > > > Google Summer of Code 2017 and successfully completed a project for > > > > implementing an inbound endpoint and a connector for IBM-MQ. > > > > > > > > I'm enthusiastic about the airavata-custos project and would be > > extremely > > > > interested in contributing to the project. I've already followed the > > wiki > > > > page[1] and the tutorial presented at the Gateways 2020 Conference > [2] > > > and > > > > I think I have a clear understanding about how custos operates in the > > > real > > > > world. > > > > > > > > As a starting point I selected the issue #152 [3] which is to > > implement a > > > > cert manager task using Custos. The idea is to automate the cert > > renewal > > > > process so that the client's won't need to manually do it by going > > > through > > > > Let's Encrypt cert renewal process. The task (cron job) will be > > > responsible > > > > for, > > > > > > > > - Connecting to Let’s Encrypt APIs and create certificates, update > > > > certificates > > > > - Saving updated certificates into a given location and where the > > > server > > > > application can use it > > > > > > > > The overall process can be illustrated as follows. > > > > > > > > > > > > > > > > - Custos Cert Renewer task (Cron Job) will be executed on periodic > > > > configurable time period > > > > - Task will communicate with Let's Encrypt using ACME(Automated > > > > Certificate Management Environments) protocol. (I've already > tested > > > this > > > > with acme4j [4] which is a java client for ACME protocol and it's > > > > working > > > > fine without any issues) > > > > - Task will then obtain the updated certificate and store it in a > > > given > > > > path in Custos (probably in a persistent volume) > > > > - Client applications can query certificates from Custos and add > > them > > > to > > > > client trustore on demand to call a server application > > > > > > > > Following I listed out some of the concerns I'm having at the moment. > > > > > > > > - In order to obtain an updated certificates, > > > > > > > > > > > > 1. we need to have an account in CA with a public and a private > key > > > > pair. Do we already have an account in Let's Encrypt for this type > > of > > > > work > > > > or Is it possible to create a dedicated account for the cert > renewer > > > > task? > > > > > > > > > > yes, we can create a test account in Let's Encrypt. > > > > > > 2. we need to provide CNs (domain names) for Let's Encrypt. Where do > > we > > > > store the domain names of the clients? > > > > > > > > > > I guess you are referring to the server application domains. those > should > > > be configurable and can be stored in a configuration file. > > > > > > > > > > - After obtaining the certificate, it's required to save it in > > Custos > > > in > > > > a given path. Do we already have an endpoint to achieve this? > > > > > > > > > > Yes, Custos has a secret management service to save certificates. > > > > > > > > > > - Client applications can query the certificates in Custos. How > can > > we > > > > provide the clients the information about the path to query? > > > > > > > > > > > > > Client applications can use Custos service accounts to access Custos > > APIs, > > > > > > > > > > > > > > Please have a look at the above and let me know your opinion. > > > > > > > > Regards > > > > > > > > [1]. > > > > > > > > > > > > > > https://cwiki.apache.org/confluence/display/CUSTOS/Custos+Architecture+and+Internals > > > > [2]. https://youtu.be/CuBvFj194Kg > > > > [3]. https://github.com/apache/airavata-custos/issues/152 > > > > [4]. https://github.com/shred/acme4j > > > > > > > > > > > > > -- > > > Research Software Engineer > > > Indiana University, IN > > > > > > > > -- > Research Software Engineer > Indiana University, IN >
