Details
-
Feature
-
Status: Dismissed (View Workflow)
-
Major
-
Resolution: Won't Fix
-
1.10
-
None
Description
Current Situation
- The Agent can be used with a Proxy product that is preferably operated on the same computer as the Agent and that stores a Proxy Server Certificate. A JobScheduler Master will request and verify the Proxy Server Certificate to secure the HTTPS communication with an Agent.
- In order to secure both Agent and Master a proposal is available with
JS-1563to have the Master respond to an Agent Proxy SSL Client Certificate request.
Desired Behavior
- Considering the fact that with
JS-1589an Agent can be configured to require an access token from any clients accessing the Agent, a simplified handling of Agent SSL Client Certificates is proposed:- The Agent will exclusively trust clients that provide an access token.
- The Agent stores an SSL Client Certificate with its local configuration.
- The Agents responds to SSL Client Certificate requests as performed e.g. by the Master when using an HTTPS communication.
Maintainer Notes
Attachments
Issue Links
- is duplicated by
-
JS-1628 HTTPS for Universal Agent, command line option -ip-address= replaced
- Released
- relates to
-
JS-1563 Agent Proxy verifies Master identity by SSL Client Certificate
- Dismissed
- requires
-
JS-1589 Agent applies token based authentication for REST web service interface
- Dismissed
- Wiki Page
-
Wiki Page Loading...