Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ensure PKI's delegated_by_realm metadata respect run-as (#91173) #91241

Conversation

ywangd
Copy link
Member

@ywangd ywangd commented Nov 2, 2022

When delegated PKI authentication is used, the delegatee's realm name is added as a metadata field. This realm name should be the effective subject's realm instead of that of the authenticating subject. This PR ensures this is the case.

Backport: #91173

When delegated PKI authentication is used, the delegatee's realm name is
added as a metadata field. This realm name should be the effective
subject's realm instead of that of the authenticating subject. This PR
ensures this is the case.
@ywangd ywangd added backport auto-merge-without-approval Automatically merge pull request when CI checks pass (NB doesn't wait for reviews!) labels Nov 2, 2022
@elasticsearchmachine elasticsearchmachine merged commit 28528b7 into elastic:8.5 Nov 2, 2022
@ywangd ywangd deleted the actual-pki-realm-delegatee-realm-8.5 branch November 2, 2022 01:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
auto-merge-without-approval Automatically merge pull request when CI checks pass (NB doesn't wait for reviews!) backport v8.5.1
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants