Skip to content
This repository has been archived by the owner on Oct 28, 2022. It is now read-only.

don't require username when certificate based authentication is used #641

Open
ghost opened this issue Aug 25, 2022 · 1 comment
Open

don't require username when certificate based authentication is used #641

ghost opened this issue Aug 25, 2022 · 1 comment

Comments

@ghost
Copy link

ghost commented Aug 25, 2022

Some servers can extract usernames from certificates. This may be as simple as extracting the common name but here is also the SPIFFE-ID which was made specifically for this purpose.

Enforcing that the user provides a username through metadata when using certificate based authentication leaves it up to the server to decide which one it should use, with some servers returning an error due to this ambiguous behaviour.

@karimra
Copy link
Owner

karimra commented Aug 25, 2022

Agree, it makes sense to not require a username/password when running a command.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant