Skip to content

Leaf cluster CA sanitizing#10741

Merged
espadolini merged 5 commits intomasterfrom
espadolini/remotecluster-ca-sanitize
Mar 3, 2022
Merged

Leaf cluster CA sanitizing#10741
espadolini merged 5 commits intomasterfrom
espadolini/remotecluster-ca-sanitize

Conversation

@espadolini
Copy link
Copy Markdown
Contributor

This also blanks the role_map and roles property of the received CA, for sanity (the role map shouldn't be relevant with host CAs).

To allow users to manually clean up spurious CAs that were injected as a result of the bug, this PR adds the ability to delete CAs with tctl:

tctl rm cert_authority/<ca type>/<ca name>

@espadolini espadolini force-pushed the espadolini/remotecluster-ca-sanitize branch from 3333c8f to 6f04c6b Compare March 2, 2022 17:34
@espadolini espadolini enabled auto-merge (squash) March 3, 2022 11:24
@espadolini espadolini merged commit 8983ede into master Mar 3, 2022
@espadolini espadolini deleted the espadolini/remotecluster-ca-sanitize branch March 3, 2022 11:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Security Issues tctl tctl - Teleport admin tool trusted-cluster

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants