Should grid-manager accept only "its" certificates? #3571

Open
opened 2020-12-21 05:09:05 +00:00 by meejah · 0 comments
meejah commented 2020-12-21 05:09:05 +00:00
Owner

When adding a grid-manager certificate to a Tahoe configuration with the "tahoe admin add-grid-manager-cert" command, the identify of the certificate is not checked.

It may be desirable to check if the public-key in the certificate matches the server's public-key. It probably makes sense to WARN only (as the operator may be getting ready to change their public key .. or for some other reason .. and could edit the config by hand anyway).

When adding a grid-manager certificate to a Tahoe configuration with the "tahoe admin add-grid-manager-cert" command, the identify of the certificate is not checked. It may be desirable to check if the public-key in the certificate matches the server's public-key. It probably makes sense to WARN only (as the operator may be getting ready to change their public key .. or for some other reason .. and could edit the config by hand anyway).
tahoe-lafs added the
code-nodeadmin
normal
enhancement
n/a
labels 2020-12-21 05:09:05 +00:00
tahoe-lafs added this to the undecided milestone 2020-12-21 05:09:05 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: tahoe-lafs/trac-2024-07-25#3571
No description provided.