hyperledger / hyperledger/fabric-samples

Kube test network : illustrate a multi-tier CA deployment using an intermediary

Open
#662 0 comments 0 reactions 0 assignees View on GitHub
test-network-k8s
Dominant language
Go
Stars
3k
Forks
3.5k
Avg merge
3d 20h
Merged PRs (30d)
6

Description

Kube test network now uses cert-manager.io to issue the TLS root (self signed Issuer) certificate and org-level TLS (CA Issuer) certificates. Similarly, the fabric-ca is used to manage a two-tier CA infrastructure for issuing ECert enrollments for node and user identities.

Extend this model by introducing an intermediate CA for both TLS and ECert issuers. The public docs provide some guidance on this front but it is still "too hard" without providing a reference to help navigate the target configuration.

Set up intermediate CAs for the Kube test network:

- TLS intermediate CA using cert-manager.io
- ECert intermediate CA using fabric-ca
- Comprehensive pass to ensure all CLI commands, config files, etc. pass the TLS _intermediate certificate_ when validating secure connections.

Ideally - show this in context of an intermediate cert with a short-term expiration and renewal process.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.