Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Make TLS certification validation configurable in the ipdevpoll Palo Alto ARP plugin #2895

Open
lunkwill42 opened this issue May 2, 2024 · 0 comments
Labels
discussion Requires developer feedback/discussion before implementation enhancement PaloAlto

Comments

@lunkwill42
Copy link
Member

Is your feature request related to a problem? Please describe.

The initial implementation of the plugin in #2613 ignores all TLS certificates by hardcoded default. This practice is very bad from a security standpoint.

Describe the solution you'd like

Really, the default should always be to verify. Options to disable verification, or to pin to a specific certificate should be added to ipdevpoll.conf. However, pinned certificates could be different for each firewall, which would require an equally stupid mechanism to pin a certificate for each Palo Alto IP device. The latter we might instead want to store as a custom attribute of the Netbox itself, and just a config option in ipdevpoll.conf to tell the plugin to use that whenever present?

Describe alternatives you've considered

Leave things as they are.

@lunkwill42 lunkwill42 added enhancement PaloAlto discussion Requires developer feedback/discussion before implementation labels May 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
discussion Requires developer feedback/discussion before implementation enhancement PaloAlto
Projects
None yet
Development

No branches or pull requests

1 participant