Hi Isuru,

Thanks for the explanation. I think I have a clear idea on how to proceed
with the Let's Encrypt part of the implementation now.

I already started the implementation and am currently designing a solution
for handling the Let's Encrypt challenge. Once that is done I am thinking
of starting the certificates store process in Custos. I think I'll probably
need some setup completed first for making authenticated requests to Custos.

Found an issue with the certificate store path in the current
implementation and I've sent a fix for that. [1]

Regards

[1]. https://github.com/apache/airavata-custos/pull/160

On Thu, May 13, 2021 at 9:31 AM Isuru Ranawaka <[email protected]> wrote:

> Hi Hasitha,
>
> Glad to hear that you have gone through the code. Please feel free to
> submit bug fixes as you see.
>
> We use HarshiCorp vault to store secrets. The paths you mentioned are
> actually created in the vault. Precisely, owner_id is the id of the user or
> the service account that owns the certificate. Token is an identifier that
> can be used to retrieve the certificate later.
>
> thanks
> Isuru
>
> On Wed, May 12, 2021 at 11:08 PM Hasitha Jayasundara <
> [email protected]> wrote:
>
> > Hi Isuru,
> >
> > Thanks for the reply. Based on your comment that custos already has an
> > endpoint to store certificates I took some time to go through the Secret
> > Management Service and the proto for Resource Secret Service.
> >
> > According to my observation, I think I can use *POST -
> > /resource-secret-management/v1.0.0/secret/certificate* endpoint to do
> > certificate uploading. (Correct me if I'm wrong)
> >
> > Going through the code I found that certificate is stored in
> > */resourcesecret/<tenant_id>/<owner_id>/ssh/<token>*. The <tenant_id>,
> > <owner_id> and <token> are received through the request body. I am not
> 100%
> > clear about <owner_id> and <token> fields in the context of custos secret
> > manager service. Could you please explain a bit about <owner_id> and the
> > <token>?
> >
> > Regards
> >
> > On Wed, May 12, 2021 at 7:30 AM Isuru Ranawaka <[email protected]>
> wrote:
> >
> > > Hi Hasitha,
> > >
> > > We really appreciate your interest in Custos project. Please find the
> > > inline comments.
> > >
> > > On Tue, May 11, 2021 at 9:33 AM Hasitha Jayasundara <
> > > [email protected]> wrote:
> > >
> > > > Hi all,
> > > >
> > > > I'm Hasitha and I'm currently working as a Full Stack Engineer for a
> UK
> > > > based tech company. I graduated from University Of Moratuwa
> Department
> > of
> > > > Electronic and Telecommunication Engineering Sri Lanka and completed
> a
> > > > software engineering internship at a company called WSO2 which is an
> > open
> > > > source technology provider based in Sri Lanka. I also participated in
> > > > Google Summer of Code 2017 and successfully completed a project for
> > > > implementing an inbound endpoint and a connector for IBM-MQ.
> > > >
> > > > I'm enthusiastic about the airavata-custos project and would be
> > extremely
> > > > interested in contributing to the project. I've already followed the
> > wiki
> > > > page[1] and the tutorial presented at the Gateways 2020 Conference
> [2]
> > > and
> > > > I think I have a clear understanding about how custos operates in the
> > > real
> > > > world.
> > > >
> > > > As a starting point I selected the issue #152 [3] which is to
> > implement a
> > > > cert manager task using Custos. The idea is to automate the cert
> > renewal
> > > > process so that the client's won't need to manually do it by going
> > > through
> > > > Let's Encrypt cert renewal process. The task (cron job) will be
> > > responsible
> > > > for,
> > > >
> > > >    - Connecting to Let’s Encrypt APIs and create certificates, update
> > > >    certificates
> > > >    - Saving updated certificates into a given location and where the
> > > server
> > > >    application can use it
> > > >
> > > > The overall process can be illustrated as follows.
> > > >
> > > >
> > > >
> > > >    - Custos Cert Renewer task (Cron Job) will be executed on periodic
> > > >    configurable time period
> > > >    - Task will communicate with Let's Encrypt using ACME(Automated
> > > >    Certificate Management Environments) protocol. (I've already
> tested
> > > this
> > > >    with acme4j [4] which is a java client for ACME protocol and it's
> > > > working
> > > >    fine without any issues)
> > > >    - Task will then obtain the updated certificate and store it in a
> > > given
> > > >    path in Custos (probably in a persistent volume)
> > > >    - Client applications can query certificates from Custos and add
> > them
> > > to
> > > >    client trustore on demand to call a server application
> > > >
> > > > Following I listed out some of the concerns I'm having at the moment.
> > > >
> > > >    - In order to obtain an updated certificates,
> > > >
> > > >
> > > >    1. we need to have an account in CA with a public and a private
> key
> > > >    pair. Do we already have an account in Let's Encrypt for this type
> > of
> > > > work
> > > >    or Is it possible to create a dedicated account for the cert
> renewer
> > > > task?
> > > >
> > >
> > > yes, we can create a test account in Let's Encrypt.
> > >
> > >    2. we need to provide CNs (domain names) for Let's Encrypt. Where do
> > we
> > > >    store the domain names of the clients?
> > > >
> > >
> > > I guess you are referring to the server application domains. those
> should
> > > be configurable and can be stored in a configuration file.
> > >
> > >
> > > >    - After obtaining the certificate, it's required to save it in
> > Custos
> > > in
> > > >    a given path. Do we already have an endpoint to achieve this?
> > > >
> > >
> > > Yes, Custos has a secret management service to save certificates.
> > >
> > >
> > > >    - Client applications can query the certificates in Custos. How
> can
> > we
> > > >    provide the clients the information about the path to query?
> > > >
> > >
> > >
> > > Client applications can use Custos service accounts to access Custos
> > APIs,
> > >
> > >
> > > >
> > > > Please have a look at the above and let me know your opinion.
> > > >
> > > > Regards
> > > >
> > > > [1].
> > > >
> > > >
> > >
> >
> https://cwiki.apache.org/confluence/display/CUSTOS/Custos+Architecture+and+Internals
> > > > [2]. https://youtu.be/CuBvFj194Kg
> > > > [3]. https://github.com/apache/airavata-custos/issues/152
> > > > [4]. https://github.com/shred/acme4j
> > > >
> > >
> > >
> > > --
> > > Research Software Engineer
> > > Indiana University, IN
> > >
> >
>
>
> --
> Research Software Engineer
> Indiana University, IN
>

Reply via email to