diff options
| author | omnom62 <omnom62@outlook.com> | 2026-09-02 20:21:38 +1000 |
|---|---|---|
| committer | omnom62 <omnom62@outlook.com> | 2026-09-02 20:21:38 +1000 |
| commit | 71ea2f3d9f654f1b3ab9e08fa6cdff4447b3fc0a (patch) | |
| tree | d2e1453a1c44e389bdb8a69f28e868dc758cc661 | |
| parent | 99decdac737629507b88c4d0390344a981a181ab (diff) | |
| download | vyos-1x-71ea2f3d9f654f1b3ab9e08fa6cdff4447b3fc0a.tar.gz vyos-1x-71ea2f3d9f654f1b3ab9e08fa6cdff4447b3fc0a.zip | |
http-api: T8989: fix mTLS trust boundary to selected CA only
Writing only the configured CA certificate to the nginx ssl_client_certificate
trust bundle instead of the full chain up to the root CA. Using find_chain()
would include the root CA, allowing sibling intermediates under the same root
to authenticate. This restricts the mTLS trust boundary to certificates issued
directly by the configured CA.
| -rwxr-xr-x | src/conf_mode/service_https.py | 21 |
1 files changed, 12 insertions, 9 deletions
diff --git a/src/conf_mode/service_https.py b/src/conf_mode/service_https.py index 52527ba63..d10825ab5 100755 --- a/src/conf_mode/service_https.py +++ b/src/conf_mode/service_https.py @@ -234,17 +234,20 @@ def generate(https): ca_name = https['certificates']['ca_certificate'] pki_ca = dict_search(f'pki.ca.{ca_name}', https) if pki_ca: - # Build chain for the selected CA only (not all configured CAs) - # to prevent any other CA from authenticating REST API clients - all_ca_certs = { - load_certificate(cert_data['certificate']) - for cert_data in dict_search('pki.ca', https, default={}).values() - } + # Write only the selected CA certificate to the nginx trust bundle. + # Using find_chain() would walk up to the root CA, allowing sibling + # intermediates under the same root to authenticate. Writing only the + # configured CA restricts the mTLS trust boundary to certificates + # issued directly by that CA. selected_ca = load_certificate(pki_ca['certificate']) - ca_chain_certs = find_chain(selected_ca, all_ca_certs) mtls_ca_path = os.path.join(cert_dir, f'{ca_name}_mtls_ca.pem') - ca_chain = '\n'.join(encode_certificate(c) for c in ca_chain_certs) - write_file(mtls_ca_path, ca_chain, user=user, group=group, mode=0o644) + write_file( + mtls_ca_path, + encode_certificate(selected_ca), + user=user, + group=group, + mode=0o644, + ) https['certificates']['mtls_ca_path'] = mtls_ca_path https['certificates']['verify_client'] = dict_search( 'certificates.verify_client', https |
