Andrew Martinez
52ed07405c
fix lint errors
2023-02-22 19:43:45 -05:00
Andrew Martinez
a4caf933f6
fixes #1310 optional KID causes controller crash
2023-02-22 15:12:07 -05:00
Paul Lorenz
e5f8d5ab60
Move heartbeat status map update outside bolt tx. Fixed #1303
2023-02-07 13:24:30 -05:00
Paul Lorenz
5c35faafa3
Fix heartbeat deadlock. Fixes #1303
...
bbolt batch was trying to finish commit, needed all txes to finish
heartbeat update in read tx was waiting for concurrent status map so it could update
heartbeat status map was locked iterating waiting to submit to batch
(now we're back at the beginning)
Was also a view tx within a view tx, which can be problematic
2023-02-06 11:53:15 -05:00
Andrew Martinez
a46a10d9eb
use new github.com/openziti/edge-api repository
...
- fixes import statements
2023-01-24 16:03:20 -05:00
Andrew Martinez
69c31fcf3e
uses github.com/openziti/edge-api
...
- removes old api specific scripts, generated files, etc
2023-01-24 14:45:24 -05:00
Paul Lorenz
7152476ced
Require config types to have a root type of object. Fixes #1279
2022-12-29 11:39:56 -05:00
Paul Lorenz
2509f9b575
update CODEOWNERS to sig-core and update MM notifications
2022-11-30 14:34:10 -05:00
Paul Lorenz
d022405ea8
Merge pull request #1235 from openziti/fill-in-client-cert-chains
...
Fill in client cert chains when enrolling
2022-11-11 16:09:18 -05:00
Paul Lorenz
90e7b0f0a6
Fill in client cert chains when enrolling
2022-11-11 14:30:55 -05:00
Andrew Martinez
d73c72679d
for #1213 delete api session on authenticator delete/re-enroll
...
- an authenticator removed or re-enrolled would continue to allow old
API Session to operate
- deleted or re-enrolled authenticators now remove associatd API
Sessions
2022-11-09 11:44:49 -05:00
Andrew Martinez
3e4f26ee78
updates edge service manager to not allow encryptionRequired to be
...
altered
2022-11-07 11:42:01 -05:00
Andrew Martinez
5dc8a66fe9
addresses #1226 api session certificate issues w/ 3rd party cas
...
- events during a multi-step transaction were immediately emitting events
causing out of order and incomplete events to be received,
specifically API Sessions w/o fingerprints
- API Session Certificates created implicitly during 3rd Party CA auth
did not properly set all properties
- adds tests
2022-11-04 14:40:07 -04:00
Paul Lorenz
63c161224a
Add linter and fix issues found by linter
2022-10-10 16:56:51 -04:00
Paul Lorenz
ad8392cef4
Update deps
2022-10-10 16:56:50 -04:00
Andrew Martinez
f802603d9f
fixes openziti/ziti#853
...
- fix nil 0 index x509 definition created
- updates x509-claims to v1.0.3 to fix x509 claim panics
2022-09-29 10:20:46 -04:00
Andrew Martinez
291eb6b509
fixes nil deref on partial jwks info
2022-09-22 09:36:46 -04:00
Andrew Martinez
60fc51253d
fixes #1176 patching externalIdClaim on CA
2022-09-15 11:18:41 -04:00
Paul Lorenz
e4d2a30399
Fix service policy patch when type isn't provided. Fixes #1169
2022-09-06 23:21:40 -04:00
Paul Lorenz
0b8a65207a
Change bootstrap check. Add hooks for isRaftEnabled
2022-08-22 12:14:40 -04:00
Paul Lorenz
0d1dfb9779
Fixes for raft command encoding and decoding
2022-08-18 12:22:30 -04:00
Paul Lorenz
a3b31eb5ed
Convert posture checks to use raft commands. Fixes #1125
2022-08-09 21:54:53 -04:00
Paul Lorenz
2e578ab784
Update identities to use raft commands. Fixes #1131
2022-08-09 14:58:23 -04:00
Paul Lorenz
4ce51b271c
Convert transit routers to use raft commands. Fixes #1132
2022-08-09 09:38:07 -04:00
Paul Lorenz
d3a4c7d0ac
Update edge routers to use raft commands. Fixes #1107
2022-08-04 10:43:21 -04:00
Paul Lorenz
5c27d8308c
Update enrollments to use raft commands. Fixes #1130
2022-08-04 10:14:39 -04:00
Paul Lorenz
fe1b0463d7
Update authenticators to use raft commands. Fixes #1099
2022-08-04 10:14:21 -04:00
Paul Lorenz
f60c06491e
Update MFA to use raft commands. Closes #1128
2022-08-02 14:56:51 -04:00
Paul Lorenz
d068397cd0
Rename controller model handler types to manager. Fixes #1124
2022-08-01 14:00:01 -04:00
Paul Lorenz
cb0a634414
Update edge services to use raft commands. Fixes #1118
2022-07-29 15:56:09 -04:00
Paul Lorenz
748036985d
Convert posture check types handler to manager. Fixes #1120
2022-07-29 15:38:58 -04:00
Paul Lorenz
3b57f19d61
Convert identity type handler to manager Fixes #1117
2022-07-29 15:36:14 -04:00
Paul Lorenz
0e827df0e2
Convert external jwt signers to raft commands. Fixes #1116
2022-07-29 14:56:56 -04:00
Paul Lorenz
9303b24547
Update service policies to use raft commands. Fixes #1111
2022-07-28 18:40:47 -04:00
Paul Lorenz
d0ed5aa00e
Update service edge router policies to use raft commands. Fixes #1110
2022-07-28 18:31:19 -04:00
Paul Lorenz
e198f16c3d
Convert edge router policies to raft commands. Fixes #1108
2022-07-28 18:30:26 -04:00
Paul Lorenz
22d36f5115
Merge pull request #1109 from openziti/raft-cas
...
Convert CAs to use raft style commands. Fixes #1100
2022-07-27 15:48:42 -04:00
Paul Lorenz
f999fae248
Merge pull request #1106 from openziti/raft-config-types
...
Raft config types
2022-07-27 15:48:28 -04:00
Paul Lorenz
8de719e31d
Merge pull request #1105 from openziti/model-refactor
...
Handles changes to UpdatedFields and EntityManager. Consolidate bolt
2022-07-27 15:48:00 -04:00
Paul Lorenz
6b9cfeac4b
Convert CAs to use raft style commands. Fixes #1100
2022-07-27 14:46:03 -04:00
Paul Lorenz
605935c224
Update config types to use raft style commands. Fixes #1101
2022-07-27 14:45:22 -04:00
Paul Lorenz
387d54adb1
Handles changes to UpdatedFields and EntityManager. Consolidate bolt
...
sink/source to edgeEntity. Make patch conversion method optional
2022-07-27 11:33:37 -04:00
Andrew Martinez
9e6cfaa47d
fixes #1103 allow multiple advertise hostnames for listeners
2022-07-26 16:06:47 -04:00
Paul Lorenz
226e87d642
Convert auth policies to use raft commands. Fixes #1097
2022-07-20 16:58:34 -04:00
Paul Lorenz
bae7e40b61
Update for foundation changes
2022-07-01 15:55:30 -04:00
Paul Lorenz
12df770d04
Update copyright
2022-06-30 17:45:08 -04:00
Paul Lorenz
b53fa0cd98
Remove event log and georegions
2022-06-30 10:35:19 -04:00
Paul Lorenz
91ea3816b8
Update for terminator terminology changes
2022-06-22 16:24:01 -04:00
Andrew Martinez
9ae2eb825c
adds jwks support
...
- ext-jwt-signers now support jwks endpoints in addition to static
certificates
- ext-jwt-signers now require either kid+cert or jkwsEndpoint
- ext-jwt-signers now requires issuer and audience fields
- jwksEndpoints are initially cached and will be revalidated on invalid
auth once every 5s at most
- adds more external id tests
2022-06-07 09:57:22 -04:00
Paul Lorenz
0c66342f8d
Update deps and address review comments
2022-06-02 23:15:23 -04:00