Commit 13fa7be
authored
improve CA and certificate generation (#2834)
Recently during an audit on a user's cluster, it was discovered that
OLM's certificate generation functionality has a few minor shortcomings.
1) The generated CA and server cert do not include a common name,
which causes some tooling to have trouble tracing the cert chain.
2) The generated CA and server cert include unnecessary key usages,
which means those certificates can be used for more than their
intended purposes.
This commit resolves the above issues by ensuring the certificates
include common names and by using the minimal key usages necessary.
Signed-off-by: Joe Lanford <joe.lanford@gmail.com>1 parent 9437498 commit 13fa7be
1 file changed
+4
-4
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
71 | 71 | | |
72 | 72 | | |
73 | 73 | | |
| 74 | + | |
74 | 75 | | |
75 | 76 | | |
76 | 77 | | |
77 | 78 | | |
78 | 79 | | |
79 | | - | |
80 | | - | |
| 80 | + | |
81 | 81 | | |
82 | 82 | | |
83 | 83 | | |
| |||
120 | 120 | | |
121 | 121 | | |
122 | 122 | | |
| 123 | + | |
123 | 124 | | |
124 | 125 | | |
125 | 126 | | |
126 | 127 | | |
127 | | - | |
128 | | - | |
| 128 | + | |
129 | 129 | | |
130 | 130 | | |
131 | 131 | | |
| |||
0 commit comments