Add TLS configuration settings/endpoints for auxiliary transports#5152
Closed
finnegancarroll wants to merge 27 commits intoopensearch-project:mainfrom
Closed
Add TLS configuration settings/endpoints for auxiliary transports#5152finnegancarroll wants to merge 27 commits intoopensearch-project:mainfrom
finnegancarroll wants to merge 27 commits intoopensearch-project:mainfrom
Conversation
Codecov ReportAttention: Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #5152 +/- ##
==========================================
+ Coverage 71.64% 71.68% +0.04%
==========================================
Files 335 335
Lines 22748 22803 +55
Branches 3599 3607 +8
==========================================
+ Hits 16297 16346 +49
- Misses 4651 4655 +4
- Partials 1800 1802 +2
🚀 New features to boost your workflow:
|
27 tasks
04ba906 to
ab18861
Compare
6 tasks
ab18861 to
5568a3c
Compare
3 tasks
Signed-off-by: Finn Carroll <carrofin@amazon.com>
Signed-off-by: Finn Carroll <carrofin@amazon.com>
Signed-off-by: Finn Carroll <carrofin@amazon.com>
Signed-off-by: Finn Carroll <carrofin@amazon.com>
Signed-off-by: Finn Carroll <carrofin@amazon.com>
Signed-off-by: Finn Carroll <carrofin@amazon.com>
Signed-off-by: Finn Carroll <carrofin@amazon.com>
Signed-off-by: Finn Carroll <carrofin@amazon.com>
…nfigDefine(SECURITY_SSL_HTTP_ENABLED) are the same test. Removing dup. Signed-off-by: Finn Carroll <carrofin@amazon.com>
…generic helper. Add aux and node-to-node transports. Signed-off-by: Finn Carroll <carrofin@amazon.com>
…h generic transport helper. Add aux transport case. Signed-off-by: Finn Carroll <carrofin@amazon.com>
…ing name instead of value. Signed-off-by: Finn Carroll <carrofin@amazon.com>
…h generic helper. Add aux transport case. Signed-off-by: Finn Carroll <carrofin@amazon.com>
Signed-off-by: Finn Carroll <carrofin@amazon.com>
Signed-off-by: Finn Carroll <carrofin@amazon.com>
… easier application to each CertType. Add aux transport cases. Signed-off-by: Finn Carroll <carrofin@amazon.com>
Signed-off-by: Finn Carroll <carrofin@amazon.com>
Signed-off-by: Finn Carroll <carrofin@amazon.com>
…ider CertType. Signed-off-by: Finn Carroll <carrofin@amazon.com>
Signed-off-by: Finn Carroll <carrofin@amazon.com>
Signed-off-by: Finn Carroll <carrofin@amazon.com>
Signed-off-by: Finn Carroll <carrofin@amazon.com>
Signed-off-by: Finn Carroll <carrofin@amazon.com>
5568a3c to
49bcba3
Compare
Signed-off-by: Finn Carroll <carrofin@amazon.com>
49bcba3 to
2745eda
Compare
This was referenced Apr 4, 2025
6 tasks
5 tasks
Contributor
Author
|
Marking this as draft while I revise. We will need a more flexible framework for configuring aux transports in security plugin to support:
|
66 tasks
Signed-off-by: Finn Carroll <carrofin@amazon.com>
Contributor
Author
|
Closing this. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Add settings for configuring keystore/truststore resources for optional auxiliary client/server transports in OpenSearch core which are supplied and registered by plugins. For more information regarding auxiliary transports see opensearch-project/OpenSearch#16534.
Initially aux transports will only support client-certificate authentication:
https://opensearch.org/docs/latest/security/authentication-backends/client-auth/
Similarly no authorization functionality is included in this PR and is planned for follow up work.
Introduces the following settings for configuring TLS for auxiliary transports:
Enable
Keystore settings
Truststore settings
Issues Resolved
#5104
Do these changes introduce new permission(s) to be displayed in the static dropdown on the front-end? If so, please open a draft PR in the security dashboards plugin and link the draft PR here
Testing
Added tests for SettingsManager and ContextManager for new transport type.
CI will fail due to missing definitions in core since the corresponding PR adding SecureAuxTransportSettingsProvider is still in review.
Check List
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.