mirror of
https://github.com/openziti/ziti.git
synced 2026-09-10 00:35:41 +00:00
8297a817b7
* fixes #3734 enforce client certificate proof-of-possession for OIDC sessions - adds verifyCertProofOfPossession() in resolveOidcSession() to require TLS client cert matching a z_cfs fingerprint or SPIFFE ID when the OIDC token was issued with cert bindings - adds z_cae (CertAllowExpired) claim from auth policy, propagated through token issuance and refresh - adds TrustCache.VerifyClientCert() with tiered pool matching (first-party roots, trust anchors, third-party) and TTL cache - adds WrapIdentityWithCertValidation() on the router to verify client certs at the TLS level against RDM PublicKeys - adds IsFirstPartyCert() on the router to gate SPIFFE ID matching by checking whether the cert chains to the controller root CA - adds VerifySpiffeId() in common/spiffehlp with SpiffeMatchApiSession, SpiffeMatchIdentity, and SpiffeMatchNone return types - adds SPIFFE IDs to OTT and token enrollment certs (/identity/<id>) - enforces cert expiry by match type: API session certs must be valid, fingerprint-matched certs respect z_cae, legacy sessions skip checks - shallow-copies leaf certs before overriding time fields in all cert verification paths to avoid races on shared x509.Certificate pointers - fixes controllerRootCache setting inited=true before the ctrl channel is available, which permanently cached the failure