elastic / elastic/endpoint

[Enhancement Request] Add support for mTLS in global artifact repository settings for air-gapped deployments

Open
#106 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Swift
Stars
47
Forks
9
PR merge metrics
No merged PRs in 30d

Description

**Describe the enhancement:**
Elastic endpoint currently allows a custom defined global artifacts base_url and verification of the server certificate of this url against a custom ca_cert. However, there are no configuration options for defining a client cert/key to provide full mTLS authentication.

**Describe a specific use case for the enhancement or feature:**
Deployment in air-gapped, secure environments with apache/nginx artifacts servers that require client certificate authentication. This aligns with the mTLS options for fleet, kibana, and elasticsearch and would result in more complete adoption of mTLS.

**What is the definition of done?**
Defend integration allows setting path variables to a PEM-encoded certificate and key for client auth. Elastic-endpoint uses the configured PEM files when downloading/refreshing artifacts.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.