aboutsummaryrefslogtreecommitdiffstats
path: root/athenz-identity-provider-service
Commit message (Collapse)AuthorAgeFilesLines
...
| * | Don't unwrap parameters as separate fieldsBjørn Christian Seime2018-03-071-15/+6
| | |
| * | ZTS server endpoint is zone specificBjørn Christian Seime2018-03-075-8/+5
| | |
| * | Rewrite server TLS init to use bootstrap identity and allow AWSBjørn Christian Seime2018-03-075-38/+19
| |/
* / Respond with HTTP-400 when source IP does not match common nameValerij Fredriksen2018-03-071-0/+4
|/
* Revert "Rewrite server TLS init to use bootstrap identity and allow AWS"Håkon Hallingstad2018-03-035-19/+38
|
* Rewrite server TLS init to use bootstrap identity and allow AWSBjørn Christian Seime2018-03-025-38/+19
|
* Don't fail on keystore on disk read/writeBjørn Christian Seime2018-03-012-9/+10
| | | | Also rename getKeystoreExpiry to getCertificateExpiry
* Cache Athenz certificate to disk. Prefer disk on load.Bjørn Christian Seime2018-03-013-32/+83
| | | | | Do not include expiry to Athenz request as they are default 30 days anyways.
* Revert "Rewrite server TLS init to use bootstrap identity and allow AWS"Harald Musum2018-02-285-32/+52
|
* Rewrite server TLS init to use bootstrap identity and allow AWSBjørn Christian Seime2018-02-285-52/+32
|
* Use Ckms instead of SecretStore in athenz-identity-provider-serviceBjørn Christian Seime2018-02-221-9/+10
|
* move identityprovider package to vespa-athenzMorten Tokle2018-02-2213-1077/+0
|
* Add zts client depMorten Tokle2018-02-221-0/+24
|
* Add bouncycastle compile scope depMorten Tokle2018-02-211-0/+10
|
* Revert "Merge pull request #5072 from vespa-engine/revert-4984-mortent/ckms"Morten Tokle2018-02-2114-73/+1091
| | | | | This reverts commit 6d7b65adfcd1e918da8173dab25bf701074f3cdc, reversing changes made to 2ecdfefd5616743f62691f64a517ab787d6f0c10.
* Revert "Refactor identityprovider. Add SiaIdentityProvider"Morten Tokle2018-02-2014-1101/+73
|
* Add bouncycastle compile scope depMorten Tokle2018-02-201-0/+10
|
* Revert "Merge pull request #5072 from vespa-engine/revert-4984-mortent/ckms"Morten Tokle2018-02-2014-73/+1091
| | | | | This reverts commit 6d7b65adfcd1e918da8173dab25bf701074f3cdc, reversing changes made to 2ecdfefd5616743f62691f64a517ab787d6f0c10.
* Revert "Refactor identityprovider. Add SiaIdentityProvider"Morten Tokle2018-02-2014-1091/+73
|
* Merge branch 'master' into mortent/ckmsMorten Tokle2018-02-201-1/+2
|\
* | Move identity provider to athenz-identity-provider-service moduleMorten Tokle2018-02-1614-73/+1090
|/
* Report config server cert expiry metricsValerij Fredriksen2018-02-063-9/+99
|
* Implement /refresh endpoint for indetity providerValerij Fredriksen2018-01-311-1/+1
|
* Add copyright headersJon Bratseth2018-01-255-0/+5
|
* Revert "Use hostname if loadBalancerAddress is not set"Valerij Fredriksen2018-01-221-4/+1
|
* Use hostname if loadBalancerAddress is not setBjørn Christian Seime2018-01-161-1/+4
|
* Use ContentSigner with BouncyCastle providerBjørn Christian Seime2018-01-161-1/+3
|
* Manually resolve remoteValerij Fredriksen2018-01-041-1/+10
|
* Remove unnecessary use of AtomicReferenceBjørn Christian Seime2017-12-061-4/+4
|
* Retrieve initial certificate in constructor for fail-fast semanticsBjørn Christian Seime2017-12-061-19/+41
|
* Don't warn when actual expiry is longer than expectedBjørn Christian Seime2017-12-061-7/+5
|
* Match issuer name defined in self-signed cert in trust storeBjørn Christian Seime2017-12-061-5/+8
|
* Merge pull request #4354 from vespa-engine/bjorncs/athenz-ca-in-truststoreBjørn Christian Seime2017-12-053-3/+9
|\ | | | | Load Athenz CA certificates to JDisc truststore
| * Load Athenz CA certificates to JDisc truststoreBjørn Christian Seime2017-12-053-3/+9
| |
* | Enable Athenz TLS certificate for mainBjørn Christian Seime2017-12-051-7/+0
|/
* Add trust store configurator with config server's CA certBjørn Christian Seime2017-12-053-1/+115
|
* Revert "Add trust store configurator with config server's CA cert"Arnstein Ressem2017-12-053-115/+1
|
* Use Extension.basicConstraints instead of cryptic string idBjørn Christian Seime2017-12-041-2/+1
|
* Add trust store configurator with config server's CA certBjørn Christian Seime2017-12-043-1/+116
|
* Split parent + container-dependency-versions from root pom.gjoranv2017-12-011-0/+1
| | | | | | - Add missing dependencies so that all provided non-yahoo jars are listed in container-dependency-versions. - Add relativePath for all child poms of parent.
* Revert "Gjoranv/split parent2"gjoranv2017-11-301-1/+0
|
* Split parent + container-dependency-versions from root pom.gjoranv2017-11-301-0/+1
| | | | | | - Add missing dependencies so that all provided non-yahoo jars are listed in container-dependency-versions. - Add relativePath for all child poms of parent.
* Revert "Gjoranv/split parent"gjoranv2017-11-291-1/+0
|
* Split parent + container-dependency-versions from root pom.gjoranv2017-11-291-0/+1
| | | | | | - Add missing dependencies so that all provided non-yahoo jars are listed in container-dependency-versions. - Add relativePath for all child poms of parent.
* Add JavaTimeModule to Jersey. Exclude Jackson from athenz bundleBjørn Christian Seime2017-11-221-5/+26
|
* Add unit test for CsrSerializedPayload deserializationBjørn Christian Seime2017-11-221-0/+32
|
* Move model types to same package as certificate signer resourceBjørn Christian Seime2017-11-223-4/+2
|
* Don't inject config instances into jax-rs resourcesBjørn Christian Seime2017-11-217-43/+31
| | | | | Injection of config instances is not suppored for jax-rs resources. All dependencies of resources must be components.
* Fix typoBjørn Christian Seime2017-11-172-2/+2
|
* Cleanup logging in IdentityDocumentResourceBjørn Christian Seime2017-11-171-2/+1
|