Commit Graph

  • 5621c1161a
    Bump google.com/api-project-999119582588/go-boringcrypto/golang in /hack dependabot[bot] 2022-04-14 13:26:21 +0000
  • 79fd8e2901
    Merge pull request #1119 from enj/enj/i/fips_log_errs Mo Khan 2022-04-14 09:19:40 -0400
  • e0886c6948
    Only emit FIPS startup log when running a server component Monis Khan 2022-04-13 17:38:12 -0400
  • f5cc2f20f7
    Merge pull request #1118 from enj/enj/i/go1.18_linter_fix Mo Khan 2022-04-13 18:15:20 -0400
  • 8fd77b72df
    Bump to go1.18.1 and fix linter errors Monis Khan 2022-04-13 16:35:06 -0400
  • 8ecf18521c
    Merge pull request #1112 from vmware-tanzu/fips-website-docs Mo Khan 2022-04-13 16:41:25 -0400
  • 96c705bf94 document how to use the fips dockerfile on our website Margo Crawford 2022-04-11 13:53:26 -0700
  • d0d20e00e4
    Merge pull request #1117 from vmware-tanzu/prefix_tokens Mo Khan 2022-04-13 15:34:42 -0400
  • 53348b8464 Add custom prefix to downstream access and refresh tokens and authcodes Ryan Richard 2022-04-13 10:13:27 -0700
  • 13daf59217
    Merge pull request #1108 from vicmarbev/main Ryan Richard 2022-04-13 08:43:39 -0700
  • 9ebf3a5b92
    Merge branch 'main' into main Ryan Richard 2022-04-13 08:41:04 -0700
  • 1dc68b19b8
    Bump golang from 1.17.8 to 1.18.1 dependabot[bot] 2022-04-13 13:51:48 +0000
  • 6af1aaeb20
    Merge pull request #1114 from enj/enj/i/fips_init_log Mo Khan 2022-04-12 16:23:38 -0400
  • 6b4fbb6e0e
    Use klog to make sure FIPS init log is emitted Monis Khan 2022-04-12 14:27:07 -0400
  • edf4ffb018
    Merge pull request #1101 from vmware-tanzu/dependabot/docker/hack/distroless/static-2556293 Mo Khan 2022-04-11 12:37:25 -0400
  • 6da394de5a
    Bump github.com/tdewolff/minify/v2 from 2.10.0 to 2.11.1 dependabot[bot] 2022-04-11 01:23:03 +0000
  • a4632db7fb
    Bump github.com/go-ldap/ldap/v3 from 3.4.2 to 3.4.3 dependabot[bot] 2022-04-08 01:31:19 +0000
  • 721526b7e7
    Bump distroless/static from 80c956f to 2556293 in /hack dependabot[bot] 2022-04-07 14:13:12 +0000
  • 91681b9368
    Update ROADMAP.md anjalitelang 2022-04-06 16:08:04 -0400
  • 3c6f97a457
    Target hack/Dockerfile_fips correctly Mo Khan 2022-04-06 15:32:08 -0400
  • 12cbd744b7
    Syntax highlighting for Dockerfile_fips Mo Khan 2022-04-06 15:31:07 -0400
  • 103538858f
    Merge pull request #1094 from vmware-tanzu/disable_http Ryan Richard 2022-04-05 12:39:04 -0700
  • bdabdf0f42 Update comment in FederationDomainTLSSpec Ryan Richard 2022-04-05 09:53:22 -0700
  • 25d20d4081 Merge branch 'main' into disable_http Ryan Richard 2022-04-05 09:00:26 -0700
  • dc24397df4 Use vmware-tanzu/carvel instead of the deprecated k14/tap to install deps with brew Víctor Martínez Bevià 2022-04-05 16:43:22 +0200
  • 6c667e7d18
    Bump google.com/api-project-999119582588/go-boringcrypto/golang in /hack dependabot[bot] 2022-04-01 17:17:47 +0000
  • 2012e4050b
    Bump golang from 1.17.8 to 1.18.0 dependabot[bot] 2022-04-01 17:17:32 +0000
  • c0874706d9
    Merge pull request #1106 from enj/enj/i/fips_followup Mo Khan 2022-04-01 13:16:50 -0400
  • 07066e020d
    Explicitly set defaultServing ciphers in FIPS mode Monis Khan 2022-03-31 17:07:47 -0400
  • 3f0753ec5a
    Remove duplication in secure TLS tests Monis Khan 2022-03-31 15:31:20 -0400
  • 15bc6a4a67
    Add more details to FIPS comments Monis Khan 2022-03-31 14:48:52 -0400
  • ce82d799c9
    Run OSSF scorecard on release branches Mo Khan 2022-04-01 10:41:23 -0400
  • a453522d81
    Add OSSF Scorecard GitHub Action Mo Khan 2022-04-01 10:30:01 -0400
  • 51c527a965 Change to camel-case for insecureAcceptExternalUnencryptedHttpRequests Ryan Richard 2022-03-31 16:23:45 -0700
  • 233c669c9f
    See if the FIPS ciphers tests fails on a diff Monis Khan 2022-03-31 06:38:48 -0400
  • ae7aac020a Merge branch 'main' into disable_http Ryan Richard 2022-03-30 11:30:32 -0700
  • 17e8faa0fe
    Have dependabot keep the FIPS dockerfile updated Mo Khan 2022-03-30 13:55:19 -0400
  • 6639ce2a1f
    Merge pull request #1061 from vmware-tanzu/fips-boringcrypto Mo Khan 2022-03-30 13:43:23 -0400
  • 53597bb824 Introduce FIPS compatibility Margo Crawford 2022-03-29 16:58:41 -0700
  • 0e54ba1a20 Slightly fancier way to prevent old values.yaml names from being used Ryan Richard 2022-03-29 14:24:40 -0700
  • b07a4131e5 Merge branch 'main' into disable_http Ryan Richard 2022-03-29 12:47:53 -0700
  • e60c71b435
    Give kube-cert-agent more resources Monis Khan 2022-03-29 11:19:33 -0400
  • 40d27f011b
    move fips dockerfile to hack directory Margo Crawford 2022-03-29 08:36:12 -0700
  • b6591ca0ae
    hard code list of ciphers Margo Crawford 2022-03-28 14:59:13 -0700
  • e5acc0e840
    import ptls rather than having a separate file with build tags Margo Crawford 2022-03-28 14:17:55 -0700
  • 565dd6f47f
    extract some of the securetls stuff into a its own shared file Margo Crawford 2022-03-25 16:38:13 -0700
  • 412e6c1441
    Cleaned up some todos, added some comments Margo Crawford 2022-03-24 11:45:50 -0700
  • 8fccce31a4
    Fix testsecuretlssupervisor Margo Crawford 2022-03-23 16:27:18 -0700
  • 6fa2c897e8
    Sort ciphers in AssertTLS Margo Crawford 2022-03-23 14:11:26 -0700
  • 2d942da0d3
    Suppress linter in supervisor_discovery_test Margo Crawford 2022-03-23 11:27:10 -0700
  • 6bf5489bbb
    Fix output for rsa 2048 suites Margo Crawford 2022-03-23 10:47:50 -0700
  • c50c4ae85b
    Change whitespace in nmap tests Margo Crawford 2022-03-23 09:33:55 -0700
  • 0a0fb7ede5
    Remove expectation for tls 1.3 nmap output Margo Crawford 2022-03-23 09:01:11 -0700
  • 0de7bc03aa
    Change order of hardcoded cipher list for fips Margo Crawford 2022-03-23 08:18:06 -0700
  • 420f855287
    override cipher suites with fips defaults in a few more places Margo Crawford 2022-03-22 14:33:45 -0700
  • 22aecf9498
    test against the default fips ciphers when cipherSuites is nil Margo Crawford 2022-03-22 12:59:04 -0700
  • a88abd7e8b
    fix compile errors in new securetls_fips_test Margo Crawford 2022-03-22 12:01:12 -0700
  • 215961b282
    Fix some linter errors, separate securetls test for fips Margo Crawford 2022-03-22 11:18:46 -0700
  • 5c6fd9c6cf
    Don't add cbc ecdhe ciphers for ldap in fips mode Margo Crawford 2022-03-21 14:59:11 -0700
  • 52c796b1f4
    supervisor discovery test shouldn't require tls 1.3 in fips mode Margo Crawford 2022-03-18 15:54:53 -0700
  • f032bc54c4
    fips only build stuff for cli Margo Crawford 2022-03-17 16:27:16 -0700
  • fb93620981
    Set secureServing minTLSVersion to 1.2 for fips Margo Crawford 2022-03-17 14:11:04 -0700
  • a036c7b4c3
    Not explicitly setting any cipher suites, just letting fips decide Margo Crawford 2022-03-16 09:48:47 -0700
  • d374b468d8
    Using different cipher suites for fips Margo Crawford 2022-03-15 16:56:29 -0700
  • 901f9fba02
    allow option to specify a different dockerfile in prepare-for-integration-tests Margo Crawford 2022-03-15 15:10:57 -0700
  • 1ee0aed054
    use init func not main func Margo Crawford 2022-03-15 08:50:51 -0700
  • 643851291a
    fips-only kubecertagent Margo Crawford 2022-03-15 08:33:21 -0700
  • 77737039af
    Fips only mode Margo Crawford 2022-03-11 09:02:17 -0800
  • 2cffea5880
    Merge pull request #1099 from vmware-tanzu/remove_supervisorhttpaddress_var Mo Khan 2022-03-29 13:36:00 -0400
  • 5f34efc0b7 Empty commit to trigger CI Ryan Richard 2022-03-29 09:39:18 -0700
  • cf471d6422 Remove unused env.SupervisorHTTPAddress integration test var Ryan Richard 2022-03-29 09:13:44 -0700
  • 3592f80457 Merge branch 'main' into disable_http Ryan Richard 2022-03-28 17:03:59 -0700
  • 488f08dd6e Provide a way to override the new HTTP loopback-only validation Ryan Richard 2022-03-28 17:03:23 -0700
  • 6b2d1539e8
    Bump github.com/creack/pty from 1.1.17 to 1.1.18 dependabot[bot] 2022-03-28 01:20:21 +0000
  • cd25cb89c4
    Merge pull request #1093 from enj/enj/d/ws1 Mo Khan 2022-03-24 20:24:29 -0400
  • 57fb085bef
    Add Workspace ONE Access docs Monis Khan 2022-03-24 17:36:35 -0400
  • 8d12c1b674 HTTP listener: default disabled and may only bind to loopback interfaces Ryan Richard 2022-03-24 15:46:10 -0700
  • b02edcdddd
    Bump github.com/spf13/cobra from 1.3.0 to 1.4.0 dependabot[bot] 2022-03-24 19:18:44 +0000
  • 8aa6e733fa
    Bump k8s.io/apiserver from 0.23.4 to 0.23.5 dependabot[bot] 2022-03-24 19:18:04 +0000
  • cb92688c06
    Bump k8s.io/apiextensions-apiserver from 0.23.4 to 0.23.5 dependabot[bot] 2022-03-24 19:18:02 +0000
  • 4e6cc83b8b
    Bump k8s.io/apimachinery from 0.23.4 to 0.23.5 dependabot[bot] 2022-03-24 19:17:59 +0000
  • 51ccea3219
    Bump k8s.io/kube-aggregator from 0.23.4 to 0.23.5 dependabot[bot] 2022-03-24 19:17:59 +0000
  • 1a1182b4c7
    Bump k8s.io/component-base from 0.23.4 to 0.23.5 dependabot[bot] 2022-03-24 19:17:57 +0000
  • 20fa8cf7c2
    Bump k8s.io/api from 0.23.4 to 0.23.5 dependabot[bot] 2022-03-24 19:17:53 +0000
  • 1192fa91dc
    Bump k8s.io/client-go from 0.23.4 to 0.23.5 dependabot[bot] 2022-03-24 19:17:53 +0000
  • 9c5adad062
    Merge pull request #1092 from vmware-tanzu/remove_oryx_direct_dep Mo Khan 2022-03-24 15:16:34 -0400
  • 4649b8e0e4
    Merge pull request #1085 from pnbrown/community-page-update Mo Khan 2022-03-24 14:02:51 -0400
  • 48c5a625a5 Remove our direct dependency on ory/x Ryan Richard 2022-03-24 10:24:54 -0700
  • a2a3fe0dfc
    Bump github.com/ory/x from 0.0.352 to 0.0.361 dependabot[bot] 2022-03-24 01:05:29 +0000
  • 42bd385cbd
    Merge pull request #1088 from vmware-tanzu/pty_int_test_flakes Ryan Richard 2022-03-22 18:10:08 -0700
  • b16058eaea
    Bump github.com/ory/x from 0.0.352 to 0.0.360 dependabot[bot] 2022-03-23 01:04:19 +0000
  • bedf4e5a39 Try to avoid getting a second username prompt in a test in e2e_test.go Ryan Richard 2022-03-22 14:23:50 -0700
  • 2715741c2c Increase a test timeout in e2e_test.go Ryan Richard 2022-03-22 12:13:10 -0700
  • d20b2056f2
    Merge branch 'main' into pty_int_test_flakes Ryan Richard 2022-03-22 11:14:19 -0700
  • a9b054e2f4
    Merge pull request #1087 from vmware-tanzu/update-install-linter-1.45.0 Margo Crawford 2022-03-22 10:57:34 -0700
  • 051a228a8c Update install-linter.sh to use v1.45.0 Margo Crawford 2022-03-22 10:29:08 -0700
  • d162e294ed Split up the context timeouts per test in e2e_test.go Ryan Richard 2022-03-22 10:17:45 -0700
  • 636d2014a7
    Merge pull request #1086 from pnbrown/patch-1 Margo Crawford 2022-03-21 15:02:05 -0700
  • f981f63b90
    Update MAINTAINERS.md Nigel Brown 2022-03-21 13:17:14 -0500
  • b5be8c6c9b Update _index.html Nigel Brown 2022-03-21 13:08:54 -0500