[
https://issues.apache.org/jira/browse/KNOX-3498?focusedWorklogId=1045087&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1045087
]
ASF GitHub Bot logged work on KNOX-3498:
----------------------------------------
Author: ASF GitHub Bot
Created on: 01/Oct/26 08:22
Start Date: 01/Oct/26 08:22
Worklog Time Spent: 10m
Work Description: smolnar82 opened a new pull request, #1438:
URL: https://github.com/apache/knox/pull/1438
[KNOX-3498](https://issues.apache.org/jira/browse/KNOX-3498) - Reject
IP-literal OIDC issuer registration via topology-configurable flag
## What changes were proposed in this pull request?
Complements the reactive IP-literal JWKS logging (PR #1437) with a
preventive, fail-fast check at **issuer registration time** so a bare-IP issuer
never enters the trust store in the first place.
- New topology-level flag `knoxidf.allow.ip.literal.issuer.url` on the
`KNOXIDF_ADMIN` service, read in `TrustedOidcIssuersResource.init()`. Default
is `true` (permissive) for backward compatibility.
- When set to `false`, `registerIssuer` rejects an `issuerUrl` whose host is
an IP literal (IPv4 or bracketed IPv6) with `400 invalid_request`, audited as
`FAILURE`. Being per-topology lets a single deployment accept IP issuers for
some admin topologies while rejecting them for a stricter one.
- Extracted the IP-literal host detection (previously duplicated in
`DefaultTokenAuthorityService` and the new resource check) into a shared
`HttpUtils.isIpLiteralHost(String)` in `gateway-util-common`, backed by Guava
`InetAddresses.isUriInetAddress`. Both call sites now delegate to it.
- Enforcement is registration-only by design; the discovery/verification
path runs off the gateway-wide singleton and stays covered by PR #1437's
warning.
## How was this patch tested?
Automated unit tests (all green):
- `HttpUtilsTest.testIsIpLiteralHost` — IPv4, bracketed IPv6, DNS names, and
null/host-less/unparseable inputs.
- `TrustedOidcIssuersResourceTest` (29) — reject-when-disabled,
allow-by-default, and `init()` param wiring.
- `DefaultTokenAuthorityServiceTest` (13) — unchanged behavior after the
refactor.
## Integration Tests
Added `test_ip_literal_issuer_registration_rejected` to
`.github/workflows/tests/test_k8s_delegation.py`: the `knoxidf-admin` topology
now sets `knoxidf.allow.ip.literal.issuer.url=false`, and the test registers a
bare-IP issuer (`https://203.0.113.5:6443`), asserting `400 invalid_request`
and that it never lands in the registry. Existing lifecycle/unregistered-issuer
cases are unaffected (they use the DNS issuer `https://k3s:6443`).
```
tests-1 | ------------------------------------
tests-1 | Your code has been rated at 10.00/10
tests-1 |
tests-1 | Waiting for knox...
tests-1 | ============================= test session starts
==============================
tests-1 | platform linux
Issue Time Tracking
-------------------
Worklog Id: (was: 1045087)
Time Spent: 1h (was: 50m)
> OIDC issuer discovery url with IP breaks when FIPS enabled.
> -----------------------------------------------------------
>
> Key: KNOX-3498
> URL: https://issues.apache.org/jira/browse/KNOX-3498
> Project: Apache Knox
> Issue Type: Bug
> Components: Server
> Reporter: Sandeep More
> Assignee: Sandeep More
> Priority: Major
> Time Spent: 1h
> Remaining Estimate: 0h
>
> A trusted OIDC issuer whose discovery url has IP (used in`jwks_uri`) breaks
> with BouncyCastle FIPS, the failure looks like a missing CA which is
> misleading.
>
> For KnoxIDF, registering a trusted OIDC issuer whose discovery document
> advertises `jwks_uri` as an IP makes token exchange fail, and the reported
> error is looks similar to trust-store misconfiguration. Example is in k8s
> : kube-apiserver advertises an IP by default, e.g.
> "jwks_uri": "https://10.83.4.208:6443/openid/v1/jwks"
>
> *Workaround:*
> 1. Knox config:
> Move the issuer onto the static verification route, which accepts an explicit
> JWKS URL list, and give it the hostname form of the endpoint:
> <param><name>jwt.expected.issuer</name>
>
> <value>KNOXSSO,https://kubernetes.default.svc.cluster.local</value></param>
> <param><name>knox.token.jwks.urls</name>
>
> <value>https://knox.example.com/gateway/knox-token/knoxtoken/api/v1/jwks.json,
>
> https://kubernetes.default.svc.cluster.local/openid/v1/jwks</value></param>
> 2. K8S Config
> Alternatively fix it at the source with kube-apiserver
> `--service-account-jwks-uri=https://kubernetes.default.svc.cluster.local/openid/v1/jwks`.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)