forked from scylladb/scylla-cluster-tests
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feature(tls-certs): add pcssibiity to generate certs/keys for each test
SCT uses a set of certificates created in 2016, for which newer TLS versions with certification checks cannot be used (particularly these old certificates don't use Subject Alternative Name extension, which would include DNS name/IP of a node for hostname verification). The change reworks how the TLS certificates/keys are created and used in SCT: - certificates/keys are created for each test run - certificates are individual for each node - SAN extension of the certificate contains DNS name and IP of that node only - added possibility to enable mutual TLS - 'stress_thread' modules are updated to build properly the c-s, s-b and latte stress commands, depending on what is enabled - tls in general, hostname validation, mtls - old certificates are deleted from SCT The related task: scylladb/qa-tasks#1605
- Loading branch information
Showing
34 changed files
with
459 additions
and
382 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file was deleted.
Oops, something went wrong.
Binary file not shown.
This file was deleted.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Binary file not shown.
Binary file not shown.
This file was deleted.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.
Oops, something went wrong.