diff options
| author | omnom62 <omnom62@outlook.com> | 2026-08-11 16:45:15 +1000 |
|---|---|---|
| committer | John Estabrook <jestabro@vyos.io> | 2026-08-26 13:33:34 -0500 |
| commit | 0cdf7e696b4deb3c3103a596bfe4d4f167dcf4b7 (patch) | |
| tree | 0d66820d71d2c193e1e7f44f73e7abfca2fa87cb /src/services | |
| parent | f3012e652edef614d4f0ed169b320106a85d83b3 (diff) | |
| download | vyos-1x-0cdf7e696b4deb3c3103a596bfe4d4f167dcf4b7.tar.gz vyos-1x-0cdf7e696b4deb3c3103a596bfe4d4f167dcf4b7.zip | |
http-api: T8989: add mTLS client certificate authentication
Add support for mutual TLS (mTLS) authentication to the VyOS REST API.
When configured, nginx requests a client certificate and verifies it
against the configured CA chain. FastAPI reads the X-Client-Verify
header set by nginx and bypasses API key/token authentication when
the client certificate is valid.
Configuration:
set service https certificates ca-certificate <name>
set service https certificates verify-client <optional|required>
Note: requires TLSv1.2 due to nginx 1.22 TLSv1.3 post-handshake
authentication limitations. TLSv1.3 support pending nginx upgrade.
Diffstat (limited to 'src/services')
| -rw-r--r-- | src/services/api/rest/routers.py | 6 |
1 files changed, 5 insertions, 1 deletions
diff --git a/src/services/api/rest/routers.py b/src/services/api/rest/routers.py index 0a43e856b..55967f57d 100644 --- a/src/services/api/rest/routers.py +++ b/src/services/api/rest/routers.py @@ -101,8 +101,12 @@ def check_auth(key_list, key): return key_id -def auth_required(data: ApiModel, x_api_key: Optional[str] = Header(None), authorization: Optional[str] = Header(None)): +def auth_required(data: ApiModel, x_api_key: Optional[str] = Header(None), authorization: Optional[str] = Header(None), x_client_verify: Optional[str] = Header(None)): session = SessionState() + # mTLS: client certificate verified by nginx against configured CA + if x_client_verify == 'SUCCESS': + session.id = 'mtls-client' + return if authorization: scheme, _, token = authorization.partition(' ') |
