* fix#3231 use root controller server certs for OIDC signing
- addresses HA vs non-HA signing
- fixes issue where APIs server w/ difference certs than the root
identity
- adds documentation for env/appenv
- adds a new composite type for TLSCert JWT signers
* address possible nil reference
* remove ineff assignment on jwt signing method
* fix#3178 apis missing from controllers, fixes#3193 adds totp auth query enrollment flag
- fixed controller store to no longer blank apis on all CUD actions
- controllers now report their current config state on leader change to
avoid stale information
- fixes peer disconnect to only set online state
- adds enrollment state flags to auth queries
- adds test for OIDC MFA enrollment/recovery/delete
- adds controller store unit tests
fixes#3084 adds events and improper chain flag
- splits cert resolution into root, legacy root + intermediate,
and third-party pool. Allowing the detection of client authentication
with incomplete chains if root + intermediate succeeds after root only fails
- adds `improperClientCertChain` to API Sessions and Current API Session.
Added for OIDC and legacy auth. Set to true when a client certificate is used
that was issued by the network and did not pass the root-only pool.
* fixes#2904 limit client certs requested/allowed
Some clients (browsers) show a popup when interacting with our TLS
servers and a pop-up or other UI to select certificates for
interacting with our server. If not limited, this causes any client cert
available to be shown, allowing the user to choose a certificate
that will never work. This fix limits the issuer's allowed so the popup
never appears or only appears with viable options.
- use new xweb to modify server TLS configs with static and 3rd party
CAs
- centralize CA certificates for re-use
* fix#2984 identity/router enrollment do not return full chains
- router extend via REST/ctrl now return full chains
- identity extend via REST now return full chains
- updates tests to allow for chain lengths
- modifies verification to look at the first cert in the chain (leaf)
- modifies edge routers to not start extension if new certs can't be
saved
- adds network-jwt tests
* fixes#2796 generated clients for enrollment do not work
- default behavior complies with OpenAPI spec, but allows for legacy PEM
handling through middleware intervention
- adds test for generic enrollment endpoint and for specific enrollment
endpoints
* fixes#2681 adds targetToken support for ext jwt signers
- adds targetToken of values ACCESS, ID for management API CRUD
- adds targetToken to client API reads
- adds --target-token to external jwt signers CLI
- updates/adds tests
- update client test
* Allow configuring endpoints file full path instead of directory. Fixes#2724
* Write initial router endpoints file based on ctrls in JWT. Fixes#2728
* Add ctrls property to non-ha router enrollment. Fixes#2108
* Enrollment doesn't contain controller which created the enrollment. Fixes#2729