mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-03 16:11:17 +08:00
generate_pki minted a CA with no key usage and server and client leaves with no Authority Key Identifier. RFC 5280 requires both, and verifiers that enforce it reject the chain: OpenSSL X509_STRICT fails with "Missing Authority Key Identifier", and Python 3.13 turned that flag on by default in ssl.create_default_context(). rustls and BoringSSL do not enforce it, so gRPC clients kept working while an HTTPS client built on Python 3.13 (for example a platform proxying to an exposed sandbox service) could not complete a handshake with a pkiInitJob-provisioned gateway at all. cert-manager PKI was unaffected. Set keyCertSign and cRLSign on the CA and use_authority_key_identifier on both leaves, matching what the sandbox L7 CA already does. Add a test that parses the bundle and asserts the extensions, including that each leaf AKI matches the CA SKI. Verified: openssl verify -x509_strict accepts both leaves, and a strict Python 3.13 client completes an mTLS handshake against a server using the new bundle where the previous bundle reproduces the failure. Signed-off-by: Max Dubrinsky <mdubrinsky@nvidia.com>
29 lines
726 B
TOML
29 lines
726 B
TOML
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
|
|
[package]
|
|
name = "openshell-bootstrap"
|
|
version.workspace = true
|
|
edition.workspace = true
|
|
license.workspace = true
|
|
repository.workspace = true
|
|
rust-version.workspace = true
|
|
|
|
[dependencies]
|
|
openshell-core = { path = "../openshell-core", default-features = false }
|
|
bytes = { workspace = true }
|
|
miette = { workspace = true }
|
|
rcgen = { workspace = true }
|
|
sha2 = { workspace = true }
|
|
serde = { workspace = true }
|
|
serde_json = { workspace = true }
|
|
tempfile = "3"
|
|
tokio = { workspace = true }
|
|
tracing = { workspace = true }
|
|
|
|
[dev-dependencies]
|
|
x509-parser = "0.16"
|
|
|
|
[lints]
|
|
workspace = true
|