Search Options

Results per page
Sort
Preferred Languages
Advance

Results 1 - 10 of 34 for crl (0.5 sec)

  1. releasenotes/notes/file-mounted-crl.yaml

    apiVersion: release-notes/v2
    kind: feature
    area: security
    releaseNotes:
      - |
        **Added** Certificate Revocation List(CRL) support for peer certificate validation based on file paths specified in 
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Mon Mar 04 08:29:38 UTC 2024
    - 303 bytes
    - Viewed (0)
  2. pilot/pkg/credentials/kube/secrets_test.go

    	}, corev1.SecretTypeTLS)
    	tlsMtlsCertSplitCaWithCrl = makeSecret("tls-mtls-split-crl-cacert", map[string]string{
    		TLSSecretCaCert: "tls-mtls-split-ca", TLSSecretCrl: "tls-mtls-split-crl",
    	}, corev1.SecretTypeTLS)
    	tlsMtlsCertSplitWithCrl = makeSecret("tls-mtls-split-crl", map[string]string{
    		TLSSecretCert: "tls-mtls-split-crl-cert", TLSSecretKey: "tls-mtls-split-crl-key",
    	}, corev1.SecretTypeTLS)
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Fri Feb 23 19:18:21 UTC 2024
    - 18.4K bytes
    - Viewed (0)
  3. tests/integration/security/egress_sidecar_tls_origination_test.go

    				CaCert:      file.AsStringOrFail(t, path.Join(env.IstioSrc, "tests/testdata/certs/dns/root-cert.pem")),
    				Crl:         file.AsStringOrFail(t, path.Join(env.IstioSrc, "tests/testdata/certs/ca.crl")),
    			}, false, apps.Ns2.Namespace.Name())
    
    			// Create a valid kubernetes secret to provision key/cert for sidecar, configured with dummy CRL
    			ingressutil.CreateIngressKubeSecretInNamespace(t, credWithDummyCRL, ingressutil.Mtls, ingressutil.IngressCredential{
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Mon Apr 08 22:02:59 UTC 2024
    - 10.4K bytes
    - Viewed (0)
  4. pilot/pkg/credentials/kube/secrets.go

    	GenericScrtKey = "key"
    	// The ID/name for the CA certificate in kubernetes generic secret.
    	GenericScrtCaCert = "cacert"
    	// The ID/name for the CRL in kubernetes generic secret.
    	GenericScrtCRL = "crl"
    
    	// The ID/name for the certificate chain in kubernetes tls secret.
    	TLSSecretCert = "tls.crt"
    	// The ID/name for the k8sKey in kubernetes tls secret.
    	TLSSecretKey = "tls.key"
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Fri Feb 23 19:18:21 UTC 2024
    - 10K bytes
    - Viewed (0)
  5. tests/integration/security/sds_ingress/ingress_test.go

    				{
    					name:       "mtls ingress gateway without CRL-client B",
    					secretName: "testmtlsgateway-secret-without-crl-b",
    					ingressGatewayCredential: ingressutil.IngressCredential{
    						PrivateKey:  ingressutil.TLSServerKeyB,
    						Certificate: ingressutil.TLSServerCertB,
    						CaCert:      ingressutil.CaCertB,
    					},
    					hostName: "testmtlsgateway-crl.example.com",
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Mon Apr 08 22:02:59 UTC 2024
    - 32.7K bytes
    - Viewed (0)
  6. src/crypto/x509/x509.go

    	// the CRL. It is used when creating a CRL and also populated when parsing a
    	// CRL. When creating a CRL, it may be empty or nil, in which case the
    	// revokedCertificates ASN.1 sequence will be omitted from the CRL entirely.
    	RevokedCertificateEntries []RevocationListEntry
    
    	// RevokedCertificates is used to populate the revokedCertificates
    Registered: Wed Jun 12 16:32:35 UTC 2024
    - Last Modified: Wed May 22 09:20:15 UTC 2024
    - 82K bytes
    - Viewed (0)
  7. tests/integration/security/egress_gateway_origination_test.go

    				CaCert:      file.AsStringOrFail(t, path.Join(env.IstioSrc, "tests/testdata/certs/dns/root-cert.pem")),
    				Crl:         file.AsStringOrFail(t, path.Join(env.IstioSrc, "tests/testdata/certs/ca.crl")),
    			}, false)
    
    			// Configured with dummy CRL
    			ingressutil.CreateIngressKubeSecret(t, credWithDummyCRL, ingressutil.Mtls, ingressutil.IngressCredential{
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Mon Apr 08 22:02:59 UTC 2024
    - 15.4K bytes
    - Viewed (0)
  8. pilot/pkg/xds/sds_test.go

    		"kubernetes://generic", "kubernetes://generic-mtls", "kubernetes://generic-mtls-cacert",
    		"kubernetes://generic-mtls-split", "kubernetes://generic-mtls-split-cacert", "kubernetes://generic-mtls-crl",
    		"kubernetes://generic-mtls-crl-cacert",
    	}
    	cases := []struct {
    		name                 string
    		proxy                *model.Proxy
    		resources            []string
    		request              *model.PushRequest
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Mon May 13 20:55:20 UTC 2024
    - 17.7K bytes
    - Viewed (0)
  9. pilot/pkg/security/model/authentication_test.go

    							ResourceApiVersion: core.ApiVersion_V3,
    						},
    					},
    				},
    			},
    		},
    		{
    			name: "MTLSStrict using SDS with CRL",
    			node: &model.Proxy{
    				Metadata: &model.NodeMetadata{},
    			},
    			validateClient: true,
    			crl:            "/custom/path/to/crl.pem",
    			expected: &auth.CommonTlsContext{
    				TlsCertificateSdsSecretConfigs: []*auth.SdsSecretConfig{
    					{
    						Name: "default",
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Tue Feb 20 22:39:21 UTC 2024
    - 18.9K bytes
    - Viewed (0)
  10. src/crypto/x509/parser.go

    		return nil, errors.New("x509: malformed tbs crl")
    	}
    	rl.RawTBSRevocationList = tbs
    	if !tbs.ReadASN1(&tbs, cryptobyte_asn1.SEQUENCE) {
    		return nil, errors.New("x509: malformed tbs crl")
    	}
    
    	var version int
    	if !tbs.PeekASN1Tag(cryptobyte_asn1.INTEGER) {
    		return nil, errors.New("x509: unsupported crl version")
    	}
    	if !tbs.ReadASN1Integer(&version) {
    Registered: Wed Jun 12 16:32:35 UTC 2024
    - Last Modified: Wed May 22 21:00:16 UTC 2024
    - 38.5K bytes
    - Viewed (0)
Back to top