-
Notifications
You must be signed in to change notification settings - Fork 2.2k
Closed
Labels
kind/featureCategorizes issue or PR as related to a new feature.Categorizes issue or PR as related to a new feature.lifecycle/rottenDenotes an issue or PR that has aged beyond stale and will be auto-closed.Denotes an issue or PR that has aged beyond stale and will be auto-closed.priority/backlogHigher priority than priority/awaiting-more-evidence.Higher priority than priority/awaiting-more-evidence.
Description
Is your feature request related to a problem? Please describe.
When creating a Certificate
CR using flag isCA: true
, there is today no possibility to specify Name Constraints to apply restrictions on the CN and SAN for this Sub-CA.
Describe the solution you'd like
a new section spec.nameConstraints
in Certificate
CR for example:
spec:
isCA: true
nameConstraints:
- type: permitted
critical: true
constraints:
dns: [.private, .corp]
ipAddress: [192.168.3.0/255.255.255.0]
- type: excluded
critical: true
constraints:
dns: [.secret.corp]
/kind feature
andreadecorte, t-cas, loa, olix0r, hoegaarden and 44 more
Metadata
Metadata
Assignees
Labels
kind/featureCategorizes issue or PR as related to a new feature.Categorizes issue or PR as related to a new feature.lifecycle/rottenDenotes an issue or PR that has aged beyond stale and will be auto-closed.Denotes an issue or PR that has aged beyond stale and will be auto-closed.priority/backlogHigher priority than priority/awaiting-more-evidence.Higher priority than priority/awaiting-more-evidence.