[ 
https://issues.apache.org/jira/browse/KNOX-3498?focusedWorklogId=1045087&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1045087
 ]

ASF GitHub Bot logged work on KNOX-3498:
----------------------------------------

                Author: ASF GitHub Bot
            Created on: 01/Oct/26 08:22
            Start Date: 01/Oct/26 08:22
    Worklog Time Spent: 10m 
      Work Description: smolnar82 opened a new pull request, #1438:
URL: https://github.com/apache/knox/pull/1438

   [KNOX-3498](https://issues.apache.org/jira/browse/KNOX-3498) - Reject 
IP-literal OIDC issuer registration via topology-configurable flag
   
   ## What changes were proposed in this pull request?
   
   Complements the reactive IP-literal JWKS logging (PR #1437) with a 
preventive, fail-fast check at **issuer registration time** so a bare-IP issuer 
never enters the trust store in the first place.
   
   - New topology-level flag `knoxidf.allow.ip.literal.issuer.url` on the 
`KNOXIDF_ADMIN` service, read in `TrustedOidcIssuersResource.init()`. Default 
is `true` (permissive) for backward compatibility.
   - When set to `false`, `registerIssuer` rejects an `issuerUrl` whose host is 
an IP literal (IPv4 or bracketed IPv6) with `400 invalid_request`, audited as 
`FAILURE`. Being per-topology lets a single deployment accept IP issuers for 
some admin topologies while rejecting them for a stricter one.
   - Extracted the IP-literal host detection (previously duplicated in 
`DefaultTokenAuthorityService` and the new resource check) into a shared 
`HttpUtils.isIpLiteralHost(String)` in `gateway-util-common`, backed by Guava 
`InetAddresses.isUriInetAddress`. Both call sites now delegate to it.
   - Enforcement is registration-only by design; the discovery/verification 
path runs off the gateway-wide singleton and stays covered by PR #1437's 
warning.
   
   ## How was this patch tested?
   
   Automated unit tests (all green):
   - `HttpUtilsTest.testIsIpLiteralHost` — IPv4, bracketed IPv6, DNS names, and 
null/host-less/unparseable inputs.
   - `TrustedOidcIssuersResourceTest` (29) — reject-when-disabled, 
allow-by-default, and `init()` param wiring.
   - `DefaultTokenAuthorityServiceTest` (13) — unchanged behavior after the 
refactor.
   
   ## Integration Tests
   
   Added `test_ip_literal_issuer_registration_rejected` to 
`.github/workflows/tests/test_k8s_delegation.py`: the `knoxidf-admin` topology 
now sets `knoxidf.allow.ip.literal.issuer.url=false`, and the test registers a 
bare-IP issuer (`https://203.0.113.5:6443`), asserting `400 invalid_request` 
and that it never lands in the registry. Existing lifecycle/unregistered-issuer 
cases are unaffected (they use the DNS issuer `https://k3s:6443`).
   ```
   tests-1  | ------------------------------------
   tests-1  | Your code has been rated at 10.00/10
   tests-1  | 
   tests-1  | Waiting for knox...
   tests-1  | ============================= test session starts 
==============================
   tests-1  | platform linux 

Issue Time Tracking
-------------------

    Worklog Id:     (was: 1045087)
    Time Spent: 1h  (was: 50m)

> OIDC issuer discovery url with IP breaks when FIPS enabled.
> -----------------------------------------------------------
>
>                 Key: KNOX-3498
>                 URL: https://issues.apache.org/jira/browse/KNOX-3498
>             Project: Apache Knox
>          Issue Type: Bug
>          Components: Server
>            Reporter: Sandeep More
>            Assignee: Sandeep More
>            Priority: Major
>          Time Spent: 1h
>  Remaining Estimate: 0h
>
> A trusted OIDC issuer whose discovery url has IP (used in`jwks_uri`) breaks 
> with BouncyCastle FIPS, the failure looks like a missing CA which is 
> misleading. 
>  
> For KnoxIDF, registering a trusted OIDC issuer whose discovery document 
> advertises `jwks_uri` as an IP makes token exchange fail, and the reported
> error is looks similar to trust-store misconfiguration. Example is in k8s
> : kube-apiserver advertises an IP by default, e.g.
>     "jwks_uri": "https://10.83.4.208:6443/openid/v1/jwks";
>  
> *Workaround:*
> 1. Knox config: 
> Move the issuer onto the static verification route, which accepts an explicit
> JWKS URL list, and give it the hostname form of the endpoint:
>     <param><name>jwt.expected.issuer</name>
>       
> <value>KNOXSSO,https://kubernetes.default.svc.cluster.local</value></param>
>     <param><name>knox.token.jwks.urls</name>
>       
> <value>https://knox.example.com/gateway/knox-token/knoxtoken/api/v1/jwks.json,
>              
> https://kubernetes.default.svc.cluster.local/openid/v1/jwks</value></param>
> 2. K8S Config 
> Alternatively fix it at the source with kube-apiserver
> `--service-account-jwks-uri=https://kubernetes.default.svc.cluster.local/openid/v1/jwks`.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to