Accept IP and short-hostname principals on sshca/signhost (#155)
ci/woodpecker/push/apply Pipeline was successful
ci/woodpecker/push/apply Pipeline was successful
Puppet signs host certs with principals hostname, FQDN and IP (plus extra IPs on k8s nodes). The signhost role only matched allowed_domains entries exactly or by suffix, so every agent run failed with `198.18.29.56 is not a valid value for valid_principals`. - Set `allowed_domains` on `sshca/signhost` to `*`, the only value OpenBao treats as unrestricted for host principals (per-entry globs are not honoured). - Note the sole-entry requirement in the config. Role stays host-only (`allow_user_certificates: false`); the CA key is untouched. Reviewed-on: #155 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #155.
This commit is contained in:
@@ -3,6 +3,8 @@ algorithm_signer: rsa-sha2-256
|
||||
ttl: 315360000 # 87600 * 3600
|
||||
allow_host_certificates: true
|
||||
allow_user_certificates: false
|
||||
allowed_domains: "unkin.net,main.unkin.net,consul"
|
||||
# "*" must be the sole entry: OpenBao only treats allowed_domains as unrestricted
|
||||
# when the whole string is "*", and otherwise matches entries exactly or by suffix.
|
||||
allowed_domains: "*"
|
||||
allow_subdomains: true
|
||||
allow_bare_domains: false
|
||||
|
||||
Reference in New Issue
Block a user