Skip to content

icinga2 console --connect: support TLS certificate verification #10890

@Al2Klimov

Description

@Al2Klimov

Is your feature request related to a problem? Please describe.

/v1/console requires high privileges. Would be a shame if a MITM sniffs such valuable credentials...

However, "The debug console does not currently support TLS certificate verification". This is bad.

Describe the solution you'd like

  • Use the well-known default Icinga PKI paths whenever connecting to a remote console
  • Allow to override via additional CLI args

Describe alternatives you've considered

Prompt the user to confirm a checksum as in icinga2 node wizard.

Additional context

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions