Search Options

Results per page
Sort
Preferred Languages
Advance

Results 41 - 50 of 390 for mtls (0.04 sec)

  1. tests/integration/ambient/testdata/global-plaintext.yaml

    # mTLS is disabled without destination rule.
    apiVersion: security.istio.io/v1beta1
    kind: PeerAuthentication
    metadata:
      name: "default"
      annotations:
        test-suite: "beta-mtls-off"
    spec:
      mtls:
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Thu Feb 16 18:55:23 UTC 2023
    - 215 bytes
    - Viewed (0)
  2. pilot/pkg/config/kube/gateway/testdata/tls.yaml.golden

        internal.istio.io/parents: Gateway/gateway/terminate-mtls.istio-system
      creationTimestamp: null
      name: gateway-istio-autogenerated-k8s-gateway-terminate-mtls
      namespace: istio-system
    spec:
      servers:
      - hosts:
        - '*/other.example'
        port:
          name: default
          number: 34000
          protocol: HTTPS
        tls:
          credentialName: kubernetes-gateway://istio-system/my-cert-http
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Fri Mar 01 20:54:36 UTC 2024
    - 4K bytes
    - Viewed (0)
  3. pilot/pkg/xds/endpoints/ep_filters_test.go

    					Mtls: &security.PeerAuthentication_MutualTLS{Mode: security.PeerAuthentication_MutualTLS_STRICT},
    				},
    			},
    			IsMtlsDisabled: false,
    		},
    		"mtls-off-global": {
    			Config: config.Config{
    				Meta: config.Meta{
    					GroupVersionKind: gvk.PeerAuthentication,
    					Name:             "mtls-off",
    					Namespace:        "istio-system",
    				},
    				Spec: &security.PeerAuthentication{
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Wed May 29 01:17:58 UTC 2024
    - 26.8K bytes
    - Viewed (0)
  4. architecture/ambient/peer-authentication.md

    the effective policy is `PERMISSIVE` (the default), the ztunnel will open a vanilla TLS HBONE tunnel (NOTE: this is not mTLS) to the Waypoint proxy and forward the traffic over that connection without presenting a client certificate. Therefore, it is absolutely critical that the waypoint proxy not assume any identity from incoming connections, even if the ztunnel is hairpinning. In other words, all traffic over TLS HBONE tunnels must be considered to be untrusted. From there, traffic is returned to...
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Wed Aug 09 22:09:18 UTC 2023
    - 3.9K bytes
    - Viewed (0)
  5. pilot/pkg/serviceregistry/kube/controller/ambient/testdata/peer-authn-disable-in.yaml

    apiVersion: security.istio.io/v1beta1
    kind: PeerAuthentication
    metadata:
      name: disable-mtls
    spec:
      mtls:
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Thu Feb 29 18:40:34 UTC 2024
    - 127 bytes
    - Viewed (0)
  6. pilot/pkg/serviceregistry/kube/controller/ambient/authorization.go

    		})
    	}
    	return res
    }
    
    func isMtlsModeUnset(mtls *v1beta1.PeerAuthentication_MutualTLS) bool {
    	return mtls == nil || mtls.Mode == v1beta1.PeerAuthentication_MutualTLS_UNSET
    }
    
    func isMtlsModeStrict(mtls *v1beta1.PeerAuthentication_MutualTLS) bool {
    	return mtls != nil && mtls.Mode == v1beta1.PeerAuthentication_MutualTLS_STRICT
    }
    
    func isMtlsModeDisable(mtls *v1beta1.PeerAuthentication_MutualTLS) bool {
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Mon Apr 15 16:23:36 UTC 2024
    - 18.4K bytes
    - Viewed (0)
  7. pilot/pkg/config/kube/gateway/testdata/tls.yaml

        hostname: "other.example"
        port: 34000
        protocol: HTTPS
        allowedRoutes:
          namespaces:
            from: All
        tls:
          mode: Terminate
          certificateRefs:
          - name: my-cert-http
          options:
            gateway.istio.io/tls-terminate-mode: MUTUAL
      - name: terminate-istio-mtls
        hostname: "egress.example"
        port: 34000
        protocol: HTTPS
        allowedRoutes:
          namespaces:
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Fri Mar 01 20:54:36 UTC 2024
    - 2K bytes
    - Viewed (0)
  8. pilot/pkg/model/authentication_test.go

    						GroupVersionKind:  gvk.PeerAuthentication,
    						CreationTimestamp: baseTimestamp,
    						Name:              "default",
    						Namespace:         "foo",
    					},
    					Spec: &securityBeta.PeerAuthentication{
    						Mtls: &securityBeta.PeerAuthentication_MutualTLS{
    							Mode: securityBeta.PeerAuthentication_MutualTLS_STRICT,
    						},
    					},
    				},
    				{
    					Meta: config.Meta{
    						GroupVersionKind:  gvk.PeerAuthentication,
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Wed Apr 17 22:20:44 UTC 2024
    - 45.1K bytes
    - Viewed (0)
  9. tests/integration/security/ca_custom_root/trust_domain_validation_test.go

    )
    
    const (
    	httpPlaintext = "http-plaintext"
    	httpMTLS      = "http-mtls"
    	tcpPlaintext  = "tcp-plaintext"
    	tcpMTLS       = "tcp-mtls"
    	tcpWL         = "tcp-wl"
    	passThrough   = "tcp-mtls-pass-through"
    
    	// policy to enable mTLS in client and server:
    	// ports with plaintext: 8090 (http) and 8092 (tcp)
    	// ports with mTLS: 8091 (http), 8093 (tcp) and 9000 (tcp passthrough).
    	policy = `
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Mon Apr 08 22:02:59 UTC 2024
    - 5.9K bytes
    - Viewed (0)
  10. releasenotes/notes/30705.yaml

    apiVersion: release-notes/v2
    kind: feature
    area: networking
    issue:
      - 28798
    
    releaseNotes:
    - |
      **Fixed** When using PeerAuthentication to turn off mTLS while using multi-network, non-mtls endpoints will be
    Registered: Fri Jun 14 15:00:06 UTC 2024
    - Last Modified: Tue Mar 30 17:53:03 UTC 2021
    - 290 bytes
    - Viewed (0)
Back to top