Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check host against CN/SAN of TLS certificate during JWT key auto-refresh #1934

Closed
letmaik opened this issue Nov 26, 2020 · 0 comments · Fixed by #1935
Closed

Check host against CN/SAN of TLS certificate during JWT key auto-refresh #1934

letmaik opened this issue Nov 26, 2020 · 0 comments · Fixed by #1935
Assignees

Comments

@letmaik
Copy link
Member

letmaik commented Nov 26, 2020

Currently, while auto-refreshing JWT keys, the stored CA cert is used to validate the TLS connection. However, the CN/SAN of the leaf cert sent within the TLS session (the actual website cert) is not checked against the domain name used for connecting.

@letmaik letmaik self-assigned this Nov 26, 2020
@letmaik letmaik changed the title Check host against CN of TLS certificate during JWT key auto-refresh Check host against CN/SAN of TLS certificate during JWT key auto-refresh Nov 26, 2020
@letmaik letmaik closed this as completed Nov 26, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant