Files
ThothII/install/dwh-auth-tls/index.html
T

131 lines
5.0 KiB
HTML

<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://git.tylconsulting.it/thothii-docs/install/dwh-auth-tls/">
<link rel="shortcut icon" href="../../img/favicon.ico">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />
<title>TLS - ThothII Docs</title>
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet">
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet">
<link href="../../css/base.css" rel="stylesheet">
<link rel="stylesheet" href="../../css/highlight.css">
<link href="../../stylesheets/extra.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
<script src="../../js/jquery-3.2.1.min.js"></script>
<script src="../../js/bootstrap-3.3.7.min.js"></script>
<script src="../../js/highlight.pack.js"></script>
<base target="_top">
<script>
var base_url = '../..';
var is_top_frame = false;
var pageToc = [
{title: "TLS for DWH REST", url: "#_top", children: [
{title: "Private CA", url: "#private-ca" },
{title: "Out-of-band fingerprint", url: "#out-of-band-fingerprint" },
{title: "Renewal", url: "#renewal" },
]},
];
</script>
<script src="../../js/base.js"></script>
<script src="../../javascripts/layout-init.js"></script>
</head>
<body>
<script>
if (is_top_frame) { $('body').addClass('wm-top-page'); }
</script>
<div class="container-fluid wm-page-content">
<a name="_top"></a>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav">
<a href="../dwh-auth-client-enrollment/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../dwh-auth-client-enrollment/" class="btn btn-xs btn-link">
Client enrollment
</a>
</div>
</div>
<h1 id="tls-for-dwh-rest">TLS for DWH REST<a class="headerlink" href="#tls-for-dwh-rest" title="Permanent link">&para;</a></h1>
<p>The DWH key may be used only over verified TLS. Authorization or availability errors never justify
disabling certificate verification.</p>
<h2 id="private-ca">Private CA<a class="headerlink" href="#private-ca" title="Permanent link">&para;</a></h2>
<p>When DWH REST uses an enterprise CA, deliver the certificate separately from the API key. The CA
is not a credential, but its integrity is part of the security boundary. Keep it out of Git and
make it unwritable by unauthorized users.</p>
<p>Esempio ACME Limited:</p>
<pre class="highlight"><code class="language-dotenv">THT_WS_ACME_EBIKES_DWH_TLS_CA_FILE=/run/secrets/acme-ebikes-dwh-ca.pem</code></pre>
<h2 id="out-of-band-fingerprint">Out-of-band fingerprint<a class="headerlink" href="#out-of-band-fingerprint" title="Permanent link">&para;</a></h2>
<p>Calculate the fingerprint of the received file and compare it through an independent channel:</p>
<pre class="highlight"><code class="language-bash">openssl x509 -noout -fingerprint -sha256 \
-in /absolute/protected/acme-ebikes-dwh-ca.pem</code></pre>
<p>The certificate SAN must include the exact name used by the binding, such as <code>dwh.acme.example</code>.</p>
<h2 id="renewal">Renewal<a class="headerlink" href="#renewal" title="Permanent link">&para;</a></h2>
<ol>
<li>Prepare the new certificate and chain.</li>
<li>Confirm the SAN and fingerprint out of band.</li>
<li>Distribute the new CA to clients while temporarily keeping the old one.</li>
<li>Update the binding and confirm connectivity with normal TLS.</li>
<li>Install the server certificate.</li>
<li>Remove the old trust after the agreed window.</li>
</ol>
<p>Do not use <code>curl -k</code>, disable TLS, or embed complete certificates or fingerprints in shared documents.</p>
<br>
<div class="row wm-article-nav-buttons" role="navigation" aria-label="navigation">
<div class="wm-article-nav">
<a href="../dwh-auth-client-enrollment/" class="btn btn-xs btn-default pull-left">
<i class="fa fa-chevron-left" aria-hidden="true"></i>
Previous</a><a href="../dwh-auth-client-enrollment/" class="btn btn-xs btn-link">
Client enrollment
</a>
</div>
</div>
<br>
</div>
<footer class="container-fluid wm-page-content">
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
</footer>
</body>
</html>