Commit Graph

3079 Commits (bfe29def59702f6d9ff322aa7df67fb5f58269f7)
 

Author SHA1 Message Date
Mariano Cano c5d3714a63 Fix acme error map 2 years ago
Mariano Cano 08815c5e90 Reneame attestation statement error 2 years ago
Mariano Cano 3cd72ac72a Remove debug statements 2 years ago
Mariano Cano 55318efe13
Merge pull request #1043 from unreality/oidc-missing-email
Allow missing Email claim in OIDC tokens
2 years ago
Mariano Cano 1b68a9f961
Merge pull request #1045 from smallstep/deprecation-notice
Add deprecation notices to step-x-init binaries
2 years ago
Mariano Cano bc61b23d91 Add deprecation notices to step-x-init binaries
Fixes #1044
2 years ago
Raal Goff b89f210469 remove fail-email test and add ok-empty-email test 2 years ago
Mariano Cano a2749ca8ed Merge branch 'master' into device-attestation 2 years ago
Raal Goff 7a03c43fe2 allow missing Email claim in OIDC tokens, use subject when its missing 2 years ago
Mariano Cano e75e7e7cd6 Fix linter warnings 2 years ago
Mariano Cano 54d92095ac Validate proof of possession signature
On the step format, validate proof of possession of the private
key validating the signature in the attestation statement.
2 years ago
Mariano Cano 45af68b244 Upgrade go.step.sm/crypto 2 years ago
Mariano Cano d718c69ad3 Prepare changelog for release 2 years ago
Mariano Cano b8162d5954
Merge pull request #1034 from smallstep/fix-1033
Fixes signature algorithm
2 years ago
Mariano Cano a7fcfe0e4e Verify with roots and intermediates 2 years ago
Mariano Cano 30c54a555d Add entry in changelog 2 years ago
Mariano Cano ea8579f3df Fix bad signature algorithm on EC+RSA PKI
When the root certificate has an EC key and he intermediate has an
RSA key, the signature algorithm of the leafs should be the default
one, SHA256WithRSA, instead of the one that the intermediate has.

Fixes #1033
2 years ago
Mariano Cano 59b7603d1e Use a clientAuth only cert for device-attest-01 2 years ago
Mariano Cano 6db631df51 Upgrade go.step.sm/crypto@attest 2 years ago
Mariano Cano ca412e77cc Return error on attestation validation
The method storeError returns a nil error
2 years ago
Mariano Cano ab5f916bd3 Define ErrorBadAttestationStatement 2 years ago
Mariano Cano 735c9d49b0 Add support for yubikey attestation 2 years ago
Mariano Cano ebce40e9b6 Add new method ACMEClient.ValidateWithPayload
This new method will be used to validate to validate the device
attestation payload.
2 years ago
Mariano Cano a893d6e7f7 Upgrade go.step.sm/cli-utils
Fixes issue with step path
2 years ago
Mariano Cano 432477aa91
Merge pull request #1030 from smallstep/herman/fix-template-validation
Add provisioner template validation
2 years ago
Mariano Cano 1938b1bb34 Merge branch 'master' into herman/fix-template-validation 2 years ago
Mariano Cano 1d1e024b84 Upgrade to go.step.sm/crypto v0.18.0 2 years ago
Mariano Cano f1c63bc38d Fix challenge mapping 2 years ago
Mariano Cano 2a44972830 Run go mod tidy 2 years ago
Mariano Cano df96b126dc Add AuthorizeChallenge unit tests 2 years ago
Mariano Cano bca311b05e Add acme property to enable challenges
Fixes #1027
2 years ago
Mariano Cano ae8d4d8757 Fix unit test 2 years ago
Herman Slatman 6b7b989988
Add provisioner template validation
Fixes #1012
2 years ago
Mariano Cano 693dc39481 Merge branch 'master' into device-attestation 2 years ago
Mariano Cano b1e9d5ee86 Revert "Run on plaintext HTTP to support Cloud Run"
This reverts commit 09b9673a60.
2 years ago
Mariano Cano dd6f59b538
Merge pull request #1024 from smallstep/gosec
Address gosec warnings
2 years ago
Mariano Cano 23b8f45b37 Address gosec warnings
Most if not all false positives
2 years ago
Mariano Cano 713dfad884
Merge pull request #1019 from smallstep/head-middleware
Add a middleware to automatically route HEAD requests to GET
2 years ago
Max 8f88740a5a
Merge pull request #1014 from smallstep/max/dns-id
Check for DNS name validity
2 years ago
Mariano Cano 6cab4d328e Add a middleware to automatically route HEAD requests to GET
Fixes #992
2 years ago
max furman c040e4b459 Add unit tests 2 years ago
Mariano Cano 85fc837dc3
Merge pull request #1018 from smallstep/ra-config
Ra config
2 years ago
Mariano Cano 3c88a9ccc2 Fixed changelog 2 years ago
Mariano Cano 8e08f0dea3 Add entries to changelog 2 years ago
Mariano Cano 0c7467ceb2 Allow to automatically configure and linked RA 2 years ago
Mariano Cano 5e0be92273 Allow option to skip the validation of config 2 years ago
max furman b7c2f6c482 Check for DNS name validity 2 years ago
Mariano Cano ae76d943c9
Merge pull request #1009 from smallstep/code-ql
Code QL
2 years ago
Mariano Cano 2db15e4eb5 Remove unnecessary log entries
These log entries add CodeQL warnings and are not necessary because
our default http.ResponseWriter allows adding log entries.
2 years ago
Mariano Cano 759aa26a57 Fix linter warning 2 years ago