Uploaded image for project: 'OpenShift Core Networking'
  1. OpenShift Core Networking
  2. CORENET-5481

Fix security issues with CNO IPSec certificate signing

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • Product / Portfolio Work
    • False
    • None
    • False
    • ---
    • 0

      In CNO we have an approver that signs certs automatically, without checking any identity information. We should modify this to require that the certificate request contains the kubelet certificate (issued separately) to ensure the identity of the client is an openshift node. We should not just hand out certificates to anyone who asks for them.

              pepalani@redhat.com Periyasamy Palanisamy
              trozet@redhat.com Tim Rozet
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: