- publishes FirstPartyX509CertValidation/ThirdPartyX509CertValidation usages and
intermediates on router data model public keys, deprecating ClientX509CertValidation
- builds the router first-party cert pool from RDM first-party keys unioned with
ctrl-channel roots; TLS and VerifyClientCert paths share buildClientCertRoots with
fallback to the deprecated usage for old controllers
- trusts the edge enrollment signing CA when verifying the certificate a router
presents on the control channel, so a signing CA outside the controller's own
trust bundle no longer refuses every router; the anchors go into a clone of the
identity's pool, never the pool its live tls.Configs share
- propagates full controller signing cert chains over the mesh via
SigningCertChainHeader and persists them in Controller store CertPem
- sends stored public keys during router sync instead of rebuilding them; publishes
controller certs leaf-only
- stops router controller reconnect loops after shutdown
- gives each in-process controller its own command decoder registry
- adds the ha-3 three-controller harness and first-party cert integration tests
- drains the cli test stdout pipe while commands run; anchors the totp token
issued-at assertion to the test clock
- backports the SPIFFE-capable test PKI from openziti/ziti#3947: --not-before on
ziti pki create, tests/testdata/create-pki.sh/.ps1, and the generated PKI under
tests/testdata/pki including the separate edge signing root and per-controller
signing intermediates; existing config sets stay on the testdata/ca PKI
- skips *.pem, *.cert and *.key files in codespell
* fixesopenziti/ziti#3356 adds www-authenticate headers
- www-authenticate headers are returned on 401s from API requests
- www-authenticate headers are returned during authentication to signal
addtional JWT bearer tokens needed (secondary ext jwt)
- adds support for additional headers on API errors
- adds SecurityTokenCtx for centralized security header processing
(legacy, jwt, etc.)
- adds SecurityCtx for centralized identity, auth policy, MFA handling
- refactors existing JWT authentication methods (oidc, legacy) to use
centralized processing where possible
* Allow routers to request current cluster membership information. Fixes#3503
* Get cluster membership information from raft directly, rather than trying to cache it in the DB. Fixes#3501
* Set a router data model timeline when initializing a new HA setup, rather than letting it stay blank. Fixes#3500
* Reduce router data model full state updates. Fixes#3504
* fix#3231 use root controller server certs for OIDC signing
- addresses HA vs non-HA signing
- fixes issue where APIs server w/ difference certs than the root
identity
- adds documentation for env/appenv
- adds a new composite type for TLSCert JWT signers
* address possible nil reference
* remove ineff assignment on jwt signing method
* fix#3178 apis missing from controllers, fixes#3193 adds totp auth query enrollment flag
- fixed controller store to no longer blank apis on all CUD actions
- controllers now report their current config state on leader change to
avoid stale information
- fixes peer disconnect to only set online state
- adds enrollment state flags to auth queries
- adds test for OIDC MFA enrollment/recovery/delete
- adds controller store unit tests