Skip to content

Don't omit CDP info for PKINIT certificates#56849

Merged
Tener merged 3 commits intomasterfrom
tener/kinit-omitcdp
Jul 16, 2025
Merged

Don't omit CDP info for PKINIT certificates#56849
Tener merged 3 commits intomasterfrom
tener/kinit-omitcdp

Conversation

@Tener
Copy link
Copy Markdown
Contributor

@Tener Tener commented Jul 16, 2025

Depending on the configuration, the CDP information may be required, so we shouldn't omit this. The change to omit CDP is very recent and didn't cause problems during tests, but some problems were reported later, so this PR changes this back.

Related to:

changelog: Improve PKINIT compatibility by always including CDP information in the certificate

Comment thread lib/srv/db/common/kerberos/kinit/ldap.go Outdated
Co-authored-by: Zac Bergquist <zac.bergquist@goteleport.com>
@public-teleport-github-review-bot public-teleport-github-review-bot bot removed the request for review from rudream July 16, 2025 16:32
@Tener Tener enabled auto-merge July 16, 2025 17:10
@Tener Tener added this pull request to the merge queue Jul 16, 2025
Merged via the queue into master with commit 3492fa4 Jul 16, 2025
40 checks passed
@Tener Tener deleted the tener/kinit-omitcdp branch July 16, 2025 17:52
@backport-bot-workflows
Copy link
Copy Markdown
Contributor

@Tener See the table below for backport results.

Branch Result
branch/v17 Failed
branch/v18 Create PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants