mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-02 07:34:45 +08:00
feat(server): separate HTTPS from mTLS authentication (#1351)
Make --tls-client-ca optional and make client certificates always optional when a CA is configured. This decouples HTTPS encryption from mTLS authentication, allowing mTLS and OIDC bearer tokens to coexist as parallel authentication mechanisms. When --tls-client-ca is provided, client certificates are validated against the CA when presented but never required. Clients may connect with or without a certificate — authentication is handled at the application layer (e.g. OIDC). Two TLS modes are now supported: - HTTPS with optional mTLS (--tls-client-ca provided) - HTTPS-only (--tls-client-ca omitted) The --disable-gateway-auth flag is preserved for backward compatibility but is now a no-op. The allow_unauthenticated field has been removed from TlsConfig. The Helm chart conditionally includes the client-ca volume and env var based on whether clientCaSecretName is configured.
This commit is contained in:
@@ -86,6 +86,9 @@ pub fn generate_pki(extra_sans: &[String]) -> Result<PkiBundle> {
|
||||
client_params
|
||||
.distinguished_name
|
||||
.push(DnType::CommonName, "openshell-client");
|
||||
client_params
|
||||
.distinguished_name
|
||||
.push(DnType::OrganizationalUnitName, "openshell-user");
|
||||
|
||||
let client_cert = client_params
|
||||
.signed_by(&client_key, &ca_cert, &ca_key)
|
||||
|
||||
Reference in New Issue
Block a user