pzampino commented on code in PR #1291:
URL: https://github.com/apache/knox/pull/1291#discussion_r3553832043
##########
gateway-util-common/src/main/java/org/apache/knox/gateway/util/X509CertificateUtil.java:
##########
@@ -73,7 +76,7 @@ public class X509CertificateUtil {
* @param algorithm the signing algorithm, eg "SHA256withRSA"
* @return self-signed X.509 certificate
*/
- public static X509Certificate generateCertificate(String dn, KeyPair pair,
int days, String algorithm) {
+ public static X509Certificate generateCertificate(String dn, KeyPair pair,
int days, String algorithm, String... ekuOids) {
Review Comment:
We'll always generate single-EKU certs with this method now? Do we need to
maintain the previous signature of this method for any reason and ADD this one
instead?
##########
gateway-spi/src/main/java/org/apache/knox/gateway/dispatch/DefaultHttpClientFactory.java:
##########
@@ -201,6 +212,11 @@ SSLContext createSSLContext(GatewayServices services,
FilterConfig filterConfig,
trustKeystore = identityKeystore;
Review Comment:
Why is the truststore the same as the identity keystore? You're reusing the
the client truststore as the Knox identity keystore in the mTLS scenario?
##########
gateway-spi/src/main/java/org/apache/knox/gateway/services/security/KeystoreService.java:
##########
@@ -34,6 +34,15 @@ public interface KeystoreService extends Service {
void addSelfSignedCertForGateway(String alias, char[] passphrase, String
hostname) throws KeystoreServiceException;
+ /**
+ * Adds a self-signed certificate to the Gateway keystore, stamping the
given Extended Key Usage
+ * purpose OIDs (single-EKU identities). The default implementation ignores
the OIDs.
+ */
+ default void addSelfSignedCertForGateway(String alias, char[] passphrase,
String hostname, String... ekuOids)
Review Comment:
What is the purpose of this new method? Is it to support self-signed
single-EKU certs for Knox?
##########
gateway-spi/src/main/java/org/apache/knox/gateway/dispatch/DefaultHttpClientFactory.java:
##########
@@ -173,25 +173,36 @@ private boolean doesRetryParamExist(final FilterConfig
filterConfig) {
* <p>
* This method is package private to allow access to unit tests
*
- * @param services the {@link GatewayServices}
- * @param filterConfig a {@link FilterConfig} used to query for parameters
for this operation
- * @param serviceRole the name of the service role to whom this HTTP client
is being created for
+ * @param services the {@link GatewayServices}
+ * @param gatewayConfig the {@link GatewayConfig} used to determine
single-EKU mode
+ * @param filterConfig a {@link FilterConfig} used to query for parameters
for this operation
+ * @param serviceRole the name of the service role to whom this HTTP
client is being created for
* @return a {@link SSLContext} or <code>null</code> if a custom {@link
SSLContext} is not needed.
*/
- SSLContext createSSLContext(GatewayServices services, FilterConfig
filterConfig, String serviceRole) {
+ SSLContext createSSLContext(GatewayServices services, GatewayConfig
gatewayConfig, FilterConfig filterConfig, String serviceRole) {
KeyStore identityKeystore;
char[] identityKeyPassphrase;
KeyStore trustKeystore;
KeystoreService ks = services.getService(ServiceType.KEYSTORE_SERVICE);
try {
- if
(Boolean.parseBoolean(filterConfig.getInitParameter(PARAMETER_USE_TWO_WAY_SSL)))
{
+ boolean singleEku = gatewayConfig != null &&
gatewayConfig.isSingleEkuEnabled();
+ boolean twoWaySsl =
Boolean.parseBoolean(filterConfig.getInitParameter(PARAMETER_USE_TWO_WAY_SSL))
+ || (gatewayConfig != null &&
gatewayConfig.isHttpClientTwoWaySslEnabled());
Review Comment:
There is global config for mTLS for dispatching (i.e.,
gatewayConfig.isHttpClientTwoWaySslEnabled())?
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]