Let cryptogen set attributes in certificates#5417
Open
johannww wants to merge 1 commit intohyperledger:mainfrom
Open
Let cryptogen set attributes in certificates#5417johannww wants to merge 1 commit intohyperledger:mainfrom
johannww wants to merge 1 commit intohyperledger:mainfrom
Conversation
This extends cryptogen functionality and allows testing ABAC chaincodes with cryptogen credentials. All defined non-admin users earn all attributes. Signed-off-by: Johann Westphall <johannwestphall@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This extends cryptogen functionality and allows testing ABAC chaincodes with cryptogen credentials. All defined non-admin users earn all attributes.
Type of change
Description
Extends cryptogen to embed user-defined attributes into X.509 certificates as a custom extension (OID 1.2.3.4.5.6.7.8.1), using the same JSON format as fabric-ca. This enables ABAC chaincode testing with cryptogen-generated credentials without requiring a Fabric CA.
This is useful for fast testing environments, without the requirement to boot a CA up and make requests user by user.
Changes:
Additional details
Unit tests were added and some generations were run and tested in a kubernetes deploy.
Release Note
Users' cryptogen-generated certs will have the attribute
abac.creatorset to true by default.