Conversation
Collaborator
Author
|
In particular: contrast this to the recommended approach currently on my hosted Redis Ltd instance: Which a: requires additional manual steps to export the pem/key file to pfx, which isn't trivial, and b: is more additional work. Sure: if you want more control, it is great to have the full options, but most people will just have the file pair. |
Collaborator
Author
|
also /cc @atakavci to a: see if there's any feedback from the Redis side, and b: (future, obvs) see if we can get updating the cloud console updated to suggest this approach. |
NickCraver
approved these changes
Apr 15, 2025
Collaborator
NickCraver
left a comment
There was a problem hiding this comment.
One quick comment - TODOs: get test server setup and docs here as follow-ups
| if (!string.IsNullOrEmpty(pfxStorageFlags)) | ||
| { | ||
| var tmp = Enum.Parse(typeof(X509KeyStorageFlags), pfxStorageFlags) as X509KeyStorageFlags?; | ||
| if (tmp is not null) storageFlags = tmp.GetValueOrDefault(); |
Collaborator
There was a problem hiding this comment.
Could use .TryParse a bit simpler here
- use Enum.TryParse for the X509 flags
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Historically, certs only worked with PFX files, which made it a pain to work with the cert pairs typically downloaded from hosts like Redis Ltd; however, on more recent .NET versions PEM is fully available. Here, we:
ConfigurationOptions(akin to the existingTrustIssuermethod) to configure certificates from filesThere are no tests added here, due to the inherent problems of CI talking to such servers; however:
works with the files downloaded from my hosted Redis Ltd endpoint:
To @philon-msft : open question: can we check Azure Redis with similar?
^^^ update: Philo assures me that Azure Redis doesn't have any relevant client-cert scenarios to consider