Skip to content

agent_auth and authd recipes - #48

Merged
tas50 merged 1 commit into
sous-chefs:masterfrom
yakara-ltd:authd
May 28, 2017
Merged

agent_auth and authd recipes#48
tas50 merged 1 commit into
sous-chefs:masterfrom
yakara-ltd:authd

Conversation

@chewi

@chewi chewi commented Sep 8, 2015

Copy link
Copy Markdown
Contributor

I'm not keen on the SSH solution, especially with both agent and server certificate verification arriving in 2.9 so I've added these recipes. They support the new certificate options but I haven't tested those yet.

This is based on my earlier packages pull request in #47. I'll rebase this one when that one gets merged, if necessary.

I really wanted to rename the existing client and server recipes to something less generic as the addition of this new approach now makes the cookbook confusing. However, I decided not to as I didn't want to upset the existing users. Perhaps now would be a good time for a clean break though as #47 will probably not be a seamless upgrade anyway. With certificate verification arriving in 2.9, perhaps this approach should replace the SSH solution entirely? The former certainly seems safer to me. Feedback on this point would be appreciated.

Only a systemd init script is provided for authd. Sorry about that.

You can easily test these recipes yourself using Kitchen. Converge the authd system first, then login, create a self-signed certificate, and converge again to start authd. On converging the agent_auth system, it should register automatically. You will need to converge the authd system one final time to actually get the server to start as client.keys would have been empty the first time around.

@chewi
chewi force-pushed the authd branch 2 times, most recently from 580d462 to a78af3f Compare November 10, 2015 14:23
@chewi
chewi force-pushed the authd branch 2 times, most recently from 06dfe96 to b9e0acc Compare November 18, 2015 17:29
@chewi

chewi commented Nov 18, 2015

Copy link
Copy Markdown
Contributor Author

This has now been rebased on #53.

@chewi

chewi commented Mar 28, 2016

Copy link
Copy Markdown
Contributor Author

Rebased.

I'm not keen on the SSH solution, especially with both agent and
server certificate verification arriving in 2.9 so I've added these
recipes. They support the new certificate options but I haven't tested
those yet.

Only a systemd init script is provided for authd. Sorry about that.

You can easily test these recipes yourself using Kitchen. Converge the
authd system first, then login, create a self-signed certificate, and
converge again to start authd. On converging the agent_auth system, it
should register automatically. You will need to converge the authd
system one final time to actually get the server to start as
client.keys would have been empty the first time around.
@chewi

chewi commented Mar 8, 2017

Copy link
Copy Markdown
Contributor Author

Well I didn't break it. 😛

@tas50
tas50 merged commit 8d53d69 into sous-chefs:master May 28, 2017
@chewi
chewi deleted the authd branch July 24, 2017 11:48
@lock

lock Bot commented Jul 24, 2018

Copy link
Copy Markdown

This thread has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@lock lock Bot locked as resolved and limited conversation to collaborators Jul 24, 2018
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants