hanicz commented on code in PR #1325: URL: https://github.com/apache/knox/pull/1325#discussion_r3854108487
########## .github/workflows/build/gateway.sh: ########## @@ -34,7 +34,15 @@ keytool -genkeypair -alias ldaps -keyalg RSA -keysize 2048 \ # 2) Store the keystore password under the alias the LDAP SSL config resolves. /knox-runtime/bin/knoxcli.sh create-alias "$KEYSTORE_PASSWORD_ALIAS" --value "$KEYSTORE_PASSWORD" -# 3) Trust that certificate in the JVM default truststore (cacerts) so the JNDI-based +# 3) Provision the gateway-level JWK required for server-managed Knox token state (renew / revoke / enable / disable and JWTProvider enforcement). +/knox-runtime/bin/knoxcli.sh generate-jwk --jwkAlg HS256 --saveAlias knox.token.hash.key + +# 4) Trust that certificate in the JVM default truststore (cacerts) so the JNDI-based +# Shiro LDAP realm accepts it. This is additive - it does not remove the default CAs. +# keytool -exportcert -alias ldaps -rfc +# -keystore "$KEYSTORE" -storepass "$KEYSTORE_PASSWORD" -file /tmp/ldaps-cert.pem + +/knox-runtime/bin/knoxcli.sh generate-jwk --jwkAlg HS256 --saveAlias knox.token.hash.key Review Comment: Why is the generate-jwk done twice? -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
