Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enforce mTLS with inception server #18

Merged
merged 1 commit into from
Nov 28, 2024
Merged

Enforce mTLS with inception server #18

merged 1 commit into from
Nov 28, 2024

Conversation

pjbgf
Copy link
Member

@pjbgf pjbgf commented Nov 28, 2024

No description provided.

Signed-off-by: Paulo Gomes <pjbgf@linux.com>
@pjbgf pjbgf merged commit 178d0c0 into main Nov 28, 2024
6 checks passed
@pjbgf pjbgf deleted the mtls branch November 28, 2024 09:09
pjbgf added a commit that referenced this pull request Feb 9, 2025
Workloads allowed to trigger mime handling require access to the
inception server. Since the [mTLS implementation](#18), this feature
stopped working as that connection could no longer be established due to
the missing client mTLS credentials.

The implementation relies on storing the mTLS data into the user
keyring, so that other processes at the host (e.g. subsequent calls to
qubesome run) are able to fetch it and inject into any workloads that
require them. Note that the workloads themselves do not access the
keyring.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant