summaryrefslogtreecommitdiff
path: root/src/services
diff options
context:
space:
mode:
authoromnom62 <omnom62@outlook.com>2026-08-11 16:45:15 +1000
committerJohn Estabrook <jestabro@vyos.io>2026-08-26 13:33:34 -0500
commit0cdf7e696b4deb3c3103a596bfe4d4f167dcf4b7 (patch)
tree0d66820d71d2c193e1e7f44f73e7abfca2fa87cb /src/services
parentf3012e652edef614d4f0ed169b320106a85d83b3 (diff)
downloadvyos-1x-0cdf7e696b4deb3c3103a596bfe4d4f167dcf4b7.tar.gz
vyos-1x-0cdf7e696b4deb3c3103a596bfe4d4f167dcf4b7.zip
http-api: T8989: add mTLS client certificate authentication
Add support for mutual TLS (mTLS) authentication to the VyOS REST API. When configured, nginx requests a client certificate and verifies it against the configured CA chain. FastAPI reads the X-Client-Verify header set by nginx and bypasses API key/token authentication when the client certificate is valid. Configuration: set service https certificates ca-certificate <name> set service https certificates verify-client <optional|required> Note: requires TLSv1.2 due to nginx 1.22 TLSv1.3 post-handshake authentication limitations. TLSv1.3 support pending nginx upgrade.
Diffstat (limited to 'src/services')
-rw-r--r--src/services/api/rest/routers.py6
1 files changed, 5 insertions, 1 deletions
diff --git a/src/services/api/rest/routers.py b/src/services/api/rest/routers.py
index 0a43e856b..55967f57d 100644
--- a/src/services/api/rest/routers.py
+++ b/src/services/api/rest/routers.py
@@ -101,8 +101,12 @@ def check_auth(key_list, key):
return key_id
-def auth_required(data: ApiModel, x_api_key: Optional[str] = Header(None), authorization: Optional[str] = Header(None)):
+def auth_required(data: ApiModel, x_api_key: Optional[str] = Header(None), authorization: Optional[str] = Header(None), x_client_verify: Optional[str] = Header(None)):
session = SessionState()
+ # mTLS: client certificate verified by nginx against configured CA
+ if x_client_verify == 'SUCCESS':
+ session.id = 'mtls-client'
+ return
if authorization:
scheme, _, token = authorization.partition(' ')