Commit Graph

270 Commits

Author SHA1 Message Date
Andrew Martinez 52ed07405c fix lint errors 2023-02-22 19:43:45 -05:00
Andrew Martinez a4caf933f6 fixes #1310 optional KID causes controller crash 2023-02-22 15:12:07 -05:00
Paul Lorenz e5f8d5ab60 Move heartbeat status map update outside bolt tx. Fixed #1303 2023-02-07 13:24:30 -05:00
Paul Lorenz 5c35faafa3 Fix heartbeat deadlock. Fixes #1303
bbolt batch was trying to finish commit, needed all txes to finish
heartbeat update in read tx was waiting for concurrent status map so it could update
heartbeat status map was locked iterating waiting to submit to batch
(now we're back at the beginning)
Was also a view tx within a view tx, which can be problematic
2023-02-06 11:53:15 -05:00
Andrew Martinez a46a10d9eb use new github.com/openziti/edge-api repository
- fixes import statements
2023-01-24 16:03:20 -05:00
Andrew Martinez 69c31fcf3e uses github.com/openziti/edge-api
- removes old api specific scripts, generated files, etc
2023-01-24 14:45:24 -05:00
Paul Lorenz 7152476ced Require config types to have a root type of object. Fixes #1279 2022-12-29 11:39:56 -05:00
Paul Lorenz 2509f9b575 update CODEOWNERS to sig-core and update MM notifications 2022-11-30 14:34:10 -05:00
Paul Lorenz d022405ea8 Merge pull request #1235 from openziti/fill-in-client-cert-chains
Fill in client cert chains when enrolling
2022-11-11 16:09:18 -05:00
Paul Lorenz 90e7b0f0a6 Fill in client cert chains when enrolling 2022-11-11 14:30:55 -05:00
Andrew Martinez d73c72679d for #1213 delete api session on authenticator delete/re-enroll
- an authenticator removed or re-enrolled would continue to allow old
  API Session to operate
- deleted or re-enrolled authenticators now remove associatd API
  Sessions
2022-11-09 11:44:49 -05:00
Andrew Martinez 3e4f26ee78 updates edge service manager to not allow encryptionRequired to be
altered
2022-11-07 11:42:01 -05:00
Andrew Martinez 5dc8a66fe9 addresses #1226 api session certificate issues w/ 3rd party cas
- events during a multi-step transaction were immediately emitting events
  causing out of order and incomplete events to be received,
  specifically API Sessions w/o fingerprints
- API Session Certificates created implicitly during 3rd Party CA auth
  did not properly set all properties
- adds tests
2022-11-04 14:40:07 -04:00
Paul Lorenz 63c161224a Add linter and fix issues found by linter 2022-10-10 16:56:51 -04:00
Paul Lorenz ad8392cef4 Update deps 2022-10-10 16:56:50 -04:00
Andrew Martinez f802603d9f fixes openziti/ziti#853
- fix nil 0 index x509 definition created
- updates x509-claims to v1.0.3 to fix x509 claim panics
2022-09-29 10:20:46 -04:00
Andrew Martinez 291eb6b509 fixes nil deref on partial jwks info 2022-09-22 09:36:46 -04:00
Andrew Martinez 60fc51253d fixes #1176 patching externalIdClaim on CA 2022-09-15 11:18:41 -04:00
Paul Lorenz e4d2a30399 Fix service policy patch when type isn't provided. Fixes #1169 2022-09-06 23:21:40 -04:00
Paul Lorenz 0b8a65207a Change bootstrap check. Add hooks for isRaftEnabled 2022-08-22 12:14:40 -04:00
Paul Lorenz 0d1dfb9779 Fixes for raft command encoding and decoding 2022-08-18 12:22:30 -04:00
Paul Lorenz a3b31eb5ed Convert posture checks to use raft commands. Fixes #1125 2022-08-09 21:54:53 -04:00
Paul Lorenz 2e578ab784 Update identities to use raft commands. Fixes #1131 2022-08-09 14:58:23 -04:00
Paul Lorenz 4ce51b271c Convert transit routers to use raft commands. Fixes #1132 2022-08-09 09:38:07 -04:00
Paul Lorenz d3a4c7d0ac Update edge routers to use raft commands. Fixes #1107 2022-08-04 10:43:21 -04:00
Paul Lorenz 5c27d8308c Update enrollments to use raft commands. Fixes #1130 2022-08-04 10:14:39 -04:00
Paul Lorenz fe1b0463d7 Update authenticators to use raft commands. Fixes #1099 2022-08-04 10:14:21 -04:00
Paul Lorenz f60c06491e Update MFA to use raft commands. Closes #1128 2022-08-02 14:56:51 -04:00
Paul Lorenz d068397cd0 Rename controller model handler types to manager. Fixes #1124 2022-08-01 14:00:01 -04:00
Paul Lorenz cb0a634414 Update edge services to use raft commands. Fixes #1118 2022-07-29 15:56:09 -04:00
Paul Lorenz 748036985d Convert posture check types handler to manager. Fixes #1120 2022-07-29 15:38:58 -04:00
Paul Lorenz 3b57f19d61 Convert identity type handler to manager Fixes #1117 2022-07-29 15:36:14 -04:00
Paul Lorenz 0e827df0e2 Convert external jwt signers to raft commands. Fixes #1116 2022-07-29 14:56:56 -04:00
Paul Lorenz 9303b24547 Update service policies to use raft commands. Fixes #1111 2022-07-28 18:40:47 -04:00
Paul Lorenz d0ed5aa00e Update service edge router policies to use raft commands. Fixes #1110 2022-07-28 18:31:19 -04:00
Paul Lorenz e198f16c3d Convert edge router policies to raft commands. Fixes #1108 2022-07-28 18:30:26 -04:00
Paul Lorenz 22d36f5115 Merge pull request #1109 from openziti/raft-cas
Convert CAs to use raft style commands. Fixes #1100
2022-07-27 15:48:42 -04:00
Paul Lorenz f999fae248 Merge pull request #1106 from openziti/raft-config-types
Raft config types
2022-07-27 15:48:28 -04:00
Paul Lorenz 8de719e31d Merge pull request #1105 from openziti/model-refactor
Handles changes to UpdatedFields and EntityManager. Consolidate bolt
2022-07-27 15:48:00 -04:00
Paul Lorenz 6b9cfeac4b Convert CAs to use raft style commands. Fixes #1100 2022-07-27 14:46:03 -04:00
Paul Lorenz 605935c224 Update config types to use raft style commands. Fixes #1101 2022-07-27 14:45:22 -04:00
Paul Lorenz 387d54adb1 Handles changes to UpdatedFields and EntityManager. Consolidate bolt
sink/source to edgeEntity. Make patch conversion method optional
2022-07-27 11:33:37 -04:00
Andrew Martinez 9e6cfaa47d fixes #1103 allow multiple advertise hostnames for listeners 2022-07-26 16:06:47 -04:00
Paul Lorenz 226e87d642 Convert auth policies to use raft commands. Fixes #1097 2022-07-20 16:58:34 -04:00
Paul Lorenz bae7e40b61 Update for foundation changes 2022-07-01 15:55:30 -04:00
Paul Lorenz 12df770d04 Update copyright 2022-06-30 17:45:08 -04:00
Paul Lorenz b53fa0cd98 Remove event log and georegions 2022-06-30 10:35:19 -04:00
Paul Lorenz 91ea3816b8 Update for terminator terminology changes 2022-06-22 16:24:01 -04:00
Andrew Martinez 9ae2eb825c adds jwks support
- ext-jwt-signers now support jwks endpoints in addition to static
  certificates
- ext-jwt-signers now require either kid+cert or jkwsEndpoint
- ext-jwt-signers now requires issuer and audience fields
- jwksEndpoints are initially cached and will be revalidated on invalid
  auth once every 5s at most
- adds more external id tests
2022-06-07 09:57:22 -04:00
Paul Lorenz 0c66342f8d Update deps and address review comments 2022-06-02 23:15:23 -04:00