Runs the router certificate fingerprint validation for router control-channel
underlay types, which was previously skipped for any connection carrying a
channel type header. Connections of other types (e.g. the raft mesh) continue to
be deferred to their own acceptor.
The already-connected / churn guard is applied only when establishing a new
channel, so additional underlays of a grouped control channel are not rejected
while the router is already connected.
- moves MarkInitialized from the end of initWeb to after config.Configure runs in Run
- prevents GetApiAddresses from caching an empty address set when an early raft mesh hello arrives before the xweb config has been populated
- ensures a controller no longer permanently advertises empty apiAddresses to its peers after losing this startup race
(cherry picked from commit 5c16993ef984f2ee89b6fed47d60e71258dc0680)
* fixesopenziti/ziti#3626 omit overlay bind points from /versions apiBaseUrls
- adds BindPointTypeUnderlay and BindPointTypeOverlay constants
- implements Type() on UnderlayBindPoint and OverlayBindPoint
- skips non-underlay bind points when building apiBaseUrls in version_router
- skips non-underlay bind points in GetApiAddresses
- adds unit tests for Type() on both bind point implementations
- updates xweb
- replaces queue-position-based window adjustment with an exponentially
decaying success rate histogram to drive grow/shrink decisions
- introduces AdaptiveRateLimitTrackerConfig with configurable
successThreshold, increaseFactor, decreaseFactor,
increaseCheckInterval, and decreaseCheckInterval
- grows window by increaseFactor when success rate exceeds threshold,
shrinks by decreaseFactor when it falls below
- renames LoadAdaptiveRateLimiterConfig to a Load method on the config
- adds currentSize and currentWindow to Success/Backoff/Failed debug logs
- updates controller TLS handshake, raft, and router ctrl rate limiters
to use the new AdaptiveRateLimitTrackerConfig
* fixes#3597, enable OIDC by default
- adds ability to have different sets of environment configs for tests
- adds ConfigSet struct as a configuration device for integration tests
- allows entire environments to be defined as needed
- original ats config set at "default-ats"
- tests that do not specify a config set, use "default-ats" as before
- standardizes configuration location, naming, etc.
- adds README.md for the above
- updates testContext to now be config set aware
- add config value to disable, update tests, changelog
- add defense against cached version data for tests
* Allow routers to request current cluster membership information. Fixes#3503
* Get cluster membership information from raft directly, rather than trying to cache it in the DB. Fixes#3501
* Set a router data model timeline when initializing a new HA setup, rather than letting it stay blank. Fixes#3500
* Reduce router data model full state updates. Fixes#3504
* restore legacy router healthcheck support for address 0.0.0.0
* restore extraneous comment
* move bindpoint to common since routers and controllers use it. put old validation back and soften message
* missed an import
* add support for and identity-driven bindPoints in controller
* cannot use ListenOptions as it pulls the go sdk into xweb :(
* more generic log message
* add ziti cli login tests in prep for continuing adding identity support in controller
* updates to tests
* updates to tests
* rebase with main
* allow login testing to external overlay
* more changes to allow a zitified ziti cli. add a test for testing login and ensure it works over a zitified connection
* refactor bindPoints to a module
* rebase with main
* no functional changes, just major refactoring based on PR requests. encapsulated all tests state into loginTestState, moved overlay to testutil
* rework a couple of util funcs to be cleaner per PR feedback
* make the new func more useful
* run tests via github action
* update changelog and remove unnecssary serveTls for now
* update from xweb v2 to v3
* change where factory is added and fix compilation issue of a test
* linting changes, move ascode test to cli_tests and activate via cli_tests
* use proper go build
* forgot to set the bin location
* fix timeout on test
* different errors on linux, windows and on gh runners
* cleanup after self-pr review
* use longer name to prevent codespell issues...
* additional changelog and add addressable terminator support
* fix out of control concatenation in cache file. fix ipv6 checking
* updates based on newer sdk and edge api client
* ensure oidc sessions auth for both older and newer commands
* add better error when url is empty and update changelog
* codespell fixes
* remove extraneous file
* update to 1.3.0 to kick off CI
* PR related changes. add interface enforcer and refactor networkIdentity
* go tidied
* fix golangci-lint and ha quickstart test
* keep fixing golanglint-ci... lol
* golanglint i was sure i'd fixed
* fix login test
* should fix ziti ops verify traffic as well
* fix verify traffic when all login information is supplied as well
* make all the timeouts longer? seems to run fine locally but fail in actions
fixes#3084 adds events and improper chain flag
- splits cert resolution into root, legacy root + intermediate,
and third-party pool. Allowing the detection of client authentication
with incomplete chains if root + intermediate succeeds after root only fails
- adds `improperClientCertChain` to API Sessions and Current API Session.
Added for OIDC and legacy auth. Set to true when a client certificate is used
that was issued by the network and did not pass the root-only pool.
* fixes#2904 limit client certs requested/allowed
Some clients (browsers) show a popup when interacting with our TLS
servers and a pop-up or other UI to select certificates for
interacting with our server. If not limited, this causes any client cert
available to be shown, allowing the user to choose a certificate
that will never work. This fix limits the issuer's allowed so the popup
never appears or only appears with viable options.
- use new xweb to modify server TLS configs with static and 3rd party
CAs
- centralize CA certificates for re-use
* closes#2860 - add validation from controller/router instead of within xweb.
allow routers to have misconfigured xweb section for healthchecks
* remove prototyping
* add changelog too
Also fix member events. We were getting add evetts on startup as the log was replayed. Store them in the
DB so we only get events when membership has actually changed.
- ziti edge login now properly probes endpoints and their return content
type along with the existing status code check
- probed endpoint responses are no longer blindly parsed
- the management endpoint is the default initial probe point, falling
back to the client version endpoint then the legacy root version
endpoint
- the SPA/ZAC bindings for web apis has been moved to the webapis folder
- improved erroring and messaging for the SPA/ZAC handling