Skip to content

KNOX-2133 - Ensure that Knox always validates TLS#203

Merged
risdenk merged 1 commit intoapache:masterfrom
risdenk:KNOX-2133
Nov 22, 2019
Merged

KNOX-2133 - Ensure that Knox always validates TLS#203
risdenk merged 1 commit intoapache:masterfrom
risdenk:KNOX-2133

Conversation

@risdenk
Copy link
Copy Markdown
Contributor

@risdenk risdenk commented Nov 21, 2019

What changes were proposed in this pull request?

Use forbiddenapis to block poor TLS usage. Note this could break some of the CLI stuff if using a self signed certificate. Fix the truststore instead :) The KnoxShell classes provide a way to properly setup the truststore.

How was this patch tested?

mvn -T.75C verify -Ppackage,release -Dshellcheck

Signed-off-by: Kevin Risden <krisden@apache.org>
@risdenk risdenk requested a review from lmccay November 21, 2019 23:26
@risdenk risdenk self-assigned this Nov 21, 2019
@risdenk risdenk merged commit 16dd645 into apache:master Nov 22, 2019
@risdenk risdenk deleted the KNOX-2133 branch November 22, 2019 00:13
stoty pushed a commit to stoty/knox that referenced this pull request May 14, 2024
…#203)

Signed-off-by: Kevin Risden <krisden@apache.org>
Signed-off-by: Kevin Risden <krisden@cloudera.com>
Change-Id: Iafa9fed53c0896687c51fcddff832dc4d26cfed5
Signed-off-by: Kevin Risden <krisden@cloudera.com>
stoty pushed a commit to stoty/knox that referenced this pull request May 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant