#4121 [RFE]: use certificate matching rule when generating SSH key from a certificate
Closed: Fixed 4 years ago by pbrezina. Opened 4 years ago by sbose.

Ticket was cloned from Red Hat Bugzilla: Bug 1580506

Currently ssh keys are generated for all valid certificate unconditionally. Certificate matching rules should be used to select suitable certificates.


Metadata Update from @sbose:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1580506

4 years ago

Metadata Update from @sbose:
- Issue assigned to sbose

4 years ago

Metadata Update from @sbose:
- Custom field patch adjusted to on

4 years ago

Commit 31ebf91 relates to this ticket

Commit 30d0ccd relates to this ticket

Commit d2da890 relates to this ticket

Commit 1a6b6c9 relates to this ticket

  • master
    • 31ebf91 - p11_child: allow verification with no_verification option
    • 30d0ccd - ssh: enable p11_child logging
    • d2da890 - ssh: add option ssh_use_certificate_matching_rules
    • 1a6b6c9 - ssh: apply certificate matching rules
    • 02d86b2 - ssh: add ssh_use_certificate_keys option to config checks

Metadata Update from @pbrezina:
- Issue close_status updated to: Fixed
- Issue status updated to: Closed (was: Open)

4 years ago
  • master
    • 849d495 - ssh: add 'no_rules' and 'all_rules' to ssh_use_certificate_matching_rules
    • f9b3c0d - ssh: do not mix different certificate lists

Commit 849d495 relates to this ticket

Commit f9b3c0d relates to this ticket

Commit 6f7f156 relates to this ticket

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/5082

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Login to comment on this ticket.

Metadata