[ 
https://issues.apache.org/jira/browse/KNOX-3359?focusedWorklogId=1028981&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1028981
 ]

ASF GitHub Bot logged work on KNOX-3359:
----------------------------------------

                Author: ASF GitHub Bot
            Created on: 09/Jul/26 18:42
            Start Date: 09/Jul/26 18:42
    Worklog Time Spent: 10m 
      Work Description: moresandeep commented on code in PR #1291:
URL: https://github.com/apache/knox/pull/1291#discussion_r3553987953


##########
gateway-spi/src/main/java/org/apache/knox/gateway/dispatch/DefaultHttpClientFactory.java:
##########
@@ -201,6 +212,11 @@ SSLContext createSSLContext(GatewayServices services, 
FilterConfig filterConfig,
           trustKeystore = identityKeystore;

Review Comment:
   THis does not look like a part of this PR, looks like it might have gotten 
shifted due to the changes. Looks like it is a fallback for when no outbound 
HTTP client truststore is configured then getTruststoreForHttpClient() returns 
null when gateway.httpclient.truststore.path isn't set. In that case we fall 
back to using its identity keystore as the trust material. 





Issue Time Tracking
-------------------

    Worklog Id:     (was: 1028981)
    Time Spent: 2.5h  (was: 2h 20m)

> Support Single-Purpose EKU Certificates
> ---------------------------------------
>
>                 Key: KNOX-3359
>                 URL: https://issues.apache.org/jira/browse/KNOX-3359
>             Project: Apache Knox
>          Issue Type: New Feature
>          Components: Server
>            Reporter: Sandeep More
>            Assignee: Sandeep More
>            Priority: Major
>          Time Spent: 2.5h
>  Remaining Estimate: 0h
>
> h1. Background
> Knox currently supports a single certificate per host. This certificate 
> carries both the serverAuth and clientAuth Extended Key Usages (EKUs), 
> meaning the same key and certificate is used whether the service running on 
> the host is acting as a TLS server or as a client in a mutual-TLS (mTLS) 
> handshake.
>  
> Industry standards and public CAs (like DigiCert) are sunsetting multi-use 
> certificates, making Knox's current requirement for dual serverAuth and 
> clientAuth EKUs difficult to manage.
> h1. Overview:
> Knox will need separate keystores and truststores for client authentication 
> and server authentication.
>  # Keystores:
>  * 
>  -- Knox to assert its identity as a server
>  -- Knox to assert its identity as a client (to downstream services)
>        2.Truststores:
>  * 
>  -- Clients asserting identity to Knox
>  -- Servers asserting identity to Knox



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to