Add support for CA certificate for auth provider #3044
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description & motivation 💭
When using an SSO provider with a certificate signed by our own internal CA, the ui server is currently unable to verify the certificate. This change adds support for providing a CA certificate to enable verification of the used certificate.
Screenshots (if applicable) 📸
N/A
Design Considerations 🎨
minimal impact, only used IF a CA cert is provided.
Testing 🧪
Added tests and I already use this to connect to a self-hosted keycloak.
How was this tested 👻
Steps for others to test: 🚶🏽♂️🚶🏽♀️
Deploy this new version & provide a caFile or caData (base64 encoded) to trust a custom certificate for SSO.
Checklists
Draft Checklist
Merge Checklist
Issue(s) closed
#2957
Docs
Any docs updates needed?
Changes required are mimimal, but the env vars for web UI should be updated with: