Repository navigation
Fixes 500 error when using PKI authentication with an incomplete certificate chain - #86700
Conversation
|
ACK: will review tomorrow |
| valid_to: validTo, | ||
| } = peerCertificate; | ||
|
|
||
| let issuerCertType: string; |
There was a problem hiding this comment.
nit: would you mind adding a comment here explaining why we do this and what every "type" means?
There was a problem hiding this comment.
Done in f2c3f3c.
FWIW, I don't think there is ever a case where a peer certificate has a null issuerCertificate value. At least, I haven't been able to reproduce that locally.
However, the way the getCertificateChain method was written previously, if the authentication process made it to this step and the peer certificate was valid but had a null issuerCertificate value, Kibana would allow the authentication attempt to proceed. I didn't want to change that behavior and potentially introduce a regression, but I can't be sure if we would encounter a null value or not, seeing as we are encountering undefined values when we shouldn't be.
|
@elasticmachine merge upstream |
💚 Build SucceededMetrics [docs]Distributable file count
History
To update your PR or re-run it, just comment with: |
azasypkin
left a comment
There was a problem hiding this comment.
Looks great, thanks! Used your certificates to confirm the error in 7.9 and that the issue doesn't happen now.
| valid_to: validTo, | ||
| } = peerCertificate; | ||
|
|
||
| // The issuerCertificate field can be three different values: |
Fixes #77121.