mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-05 00:44:25 +08:00
generate_pki minted a CA with no key usage and server and client leaves with no Authority Key Identifier. RFC 5280 requires both, and verifiers that enforce it reject the chain: OpenSSL X509_STRICT fails with "Missing Authority Key Identifier", and Python 3.13 turned that flag on by default in ssl.create_default_context(). rustls and BoringSSL do not enforce it, so gRPC clients kept working while an HTTPS client built on Python 3.13 (for example a platform proxying to an exposed sandbox service) could not complete a handshake with a pkiInitJob-provisioned gateway at all. cert-manager PKI was unaffected. Set keyCertSign and cRLSign on the CA and use_authority_key_identifier on both leaves, matching what the sandbox L7 CA already does. Add a test that parses the bundle and asserts the extensions, including that each leaf AKI matches the CA SKI. Verified: openssl verify -x509_strict accepts both leaves, and a strict Python 3.13 client completes an mTLS handshake against a server using the new bundle where the previous bundle reproduces the failure. Signed-off-by: Max Dubrinsky <mdubrinsky@nvidia.com>