Skip to content

Certserver hardening#300

Open
rimasgo wants to merge 2 commits intoIshentRas:masterfrom
rimasgo:certserver_hardening
Open

Certserver hardening#300
rimasgo wants to merge 2 commits intoIshentRas:masterfrom
rimasgo:certserver_hardening

Conversation

@rimasgo
Copy link
Copy Markdown

@rimasgo rimasgo commented Oct 7, 2019

  1. Changes added for protocol selection for retrieving certificates from certificate server. By default HTTP will be used.
  2. Added possibility to specify headers to remote_file resource for certificate retrieval if custom headers (authentication e.g.) should be sent to certificate server.
  3. Added .htaccess for ca.crt access;
  4. Added .htaccess for node certificates;
  5. Modified NetworkManager dispatcher script to add nameservers instead of replacing - no impact to existing environments. Default route interface's IP address will be added as the first entry into /etc/resolv.conf unless it's there already.

…rary. replaced hardcoded http proctocol with variable
… rather than to replace it (fixes nip.io issues in kitchen). Added headers option for remote_file - certificate retrieval in case of server hardening required. .htaccess for node certificates
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant