[ 
https://issues.apache.org/jira/browse/KNOX-3498?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18121475#comment-18121475
 ] 

ASF subversion and git services commented on KNOX-3498:
-------------------------------------------------------

Commit 9bb221513c9bf893687427fbf4698c60dd9db2fa in knox's branch 
refs/heads/master from Sandeep Moré
[ https://gitbox.apache.org/repos/asf?p=knox.git;h=9bb221513 ]

KNOX-3498 - In cases of failures with OIDC issuer discovery url containing IP 
addresses log a proper error and warn message. (#1437)

> OIDC issuer discovery url with IP breaks when FIPS enabled.
> -----------------------------------------------------------
>
>                 Key: KNOX-3498
>                 URL: https://issues.apache.org/jira/browse/KNOX-3498
>             Project: Apache Knox
>          Issue Type: Bug
>          Components: Server
>            Reporter: Sandeep More
>            Assignee: Sandeep More
>            Priority: Major
>          Time Spent: 50m
>  Remaining Estimate: 0h
>
> A trusted OIDC issuer whose discovery url has IP (used in`jwks_uri`) breaks 
> with BouncyCastle FIPS, the failure looks like a missing CA which is 
> misleading. 
>  
> For KnoxIDF, registering a trusted OIDC issuer whose discovery document 
> advertises `jwks_uri` as an IP makes token exchange fail, and the reported
> error is looks similar to trust-store misconfiguration. Example is in k8s
> : kube-apiserver advertises an IP by default, e.g.
>     "jwks_uri": "https://10.83.4.208:6443/openid/v1/jwks";
>  
> *Workaround:*
> 1. Knox config: 
> Move the issuer onto the static verification route, which accepts an explicit
> JWKS URL list, and give it the hostname form of the endpoint:
>     <param><name>jwt.expected.issuer</name>
>       
> <value>KNOXSSO,https://kubernetes.default.svc.cluster.local</value></param>
>     <param><name>knox.token.jwks.urls</name>
>       
> <value>https://knox.example.com/gateway/knox-token/knoxtoken/api/v1/jwks.json,
>              
> https://kubernetes.default.svc.cluster.local/openid/v1/jwks</value></param>
> 2. K8S Config 
> Alternatively fix it at the source with kube-apiserver
> `--service-account-jwks-uri=https://kubernetes.default.svc.cluster.local/openid/v1/jwks`.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to