Add the service-to-service module
This commit is contained in:
43
service-to-service/docs/output/06-mtls.txt
Normal file
43
service-to-service/docs/output/06-mtls.txt
Normal file
@@ -0,0 +1,43 @@
|
||||
==============================================================================
|
||||
docs/output/06-mtls.txt
|
||||
Client-certificate authentication on port 8443, server.ssl.client-auth=need.
|
||||
Certificates from scripts/certs.sh. edge.crt and rogue.crt have IDENTICAL subjects and
|
||||
different issuers.
|
||||
==============================================================================
|
||||
|
||||
$ openssl x509 -in target/certs/edge.crt -noout -subject -issuer
|
||||
subject=CN = edge-service, OU = payments
|
||||
issuer=CN = Internal Mesh CA
|
||||
$ openssl x509 -in target/certs/rogue.crt -noout -subject -issuer
|
||||
subject=CN = edge-service, OU = payments
|
||||
issuer=CN = Some Other CA
|
||||
|
||||
$ curl --cert edge.crt --key edge.key https://localhost:8443/mtls/whoami
|
||||
{
|
||||
"principal": "edge-service",
|
||||
"authenticationType": "PreAuthenticatedAuthenticationToken",
|
||||
"authorities": [
|
||||
"ROLE_SERVICE",
|
||||
"FACTOR_X509"
|
||||
],
|
||||
"certificateSubject": "OU=payments,CN=edge-service",
|
||||
"certificateIssuer": "CN=Internal Mesh CA"
|
||||
}
|
||||
|
||||
$ curl --cert rogue.crt --key rogue.key https://localhost:8443/mtls/whoami
|
||||
[curl exit 56, http 000]
|
||||
|
||||
$ curl https://localhost:8443/mtls/trusted-header # a permitAll() endpoint
|
||||
[curl exit 56, http 000]
|
||||
|
||||
$ curl --cert edge.crt --key edge.key -H 'X-Client-Cert-Subject: CN=payments-service' \
|
||||
https://localhost:8443/mtls/trusted-header
|
||||
{"caller":"CN=payments-service","verifiedBy":"nothing. This endpoint believes a header."}
|
||||
|
||||
# Three things worth reading twice.
|
||||
# 1. The rogue certificate fails with curl exit 56 and NO http status. The handshake
|
||||
# is rejected; the application never sees a request and logs nothing at INFO.
|
||||
# 2. So does the permitAll() endpoint. client-auth=need is a property of the
|
||||
# CONNECTOR, not of a path. You cannot expose a public endpoint on that port.
|
||||
# 3. The last call is what a mesh deployment usually looks like from inside the
|
||||
# application: an identity taken from a header, verified by nothing.
|
||||
Reference in New Issue
Block a user