Add support for CA root certificate to Fleet Desktop (fleetctl package's --fleet-certificate flag) (#6312)

* Orbit to pass the value of `--fleet-certificate` to Fleet Desktop

* Add changes for testing
This commit is contained in:
Lucas Manuel Rodriguez
2022-06-21 16:25:36 -03:00
committed by GitHub
parent b1442e6e55
commit 9b210fc6bd
7 changed files with 55 additions and 34 deletions
+13 -9
View File
@@ -9,20 +9,21 @@ Scripts in this directory aim to ease the testing of Orbit and the [TUF](https:/
The `main.sh` creates and runs the TUF repository and optionally generate the installers (GENERATE_PKGS):
```sh
SYSTEMS="macos windows linux" \
PKG_FLEET_URL=https://127.0.0.1:8080 \
PKG_TUF_URL=http://127.0.0.1:8081 \
DEB_FLEET_URL=https://172.16.132.1:8080 \
DEB_TUF_URL=http://172.16.132.1:8081 \
RPM_FLEET_URL=https://172.16.132.1:8080 \
RPM_TUF_URL=http://172.16.132.1:8081 \
MSI_FLEET_URL=https://172.16.132.1:8080 \
MSI_TUF_URL=http://172.16.132.1:8081 \
PKG_FLEET_URL=https://localhost:8080 \
PKG_TUF_URL=http://localhost:8081 \
DEB_FLEET_URL=https://host.docker.internal:8080 \
DEB_TUF_URL=http://host.docker.internal:8081 \
RPM_FLEET_URL=https://host.docker.internal:8080 \
RPM_TUF_URL=http://host.docker.internal:8081 \
MSI_FLEET_URL=https://host.docker.internal:8080 \
MSI_TUF_URL=http://host.docker.internal:8081 \
GENERATE_PKG=1 \
GENERATE_DEB=1 \
GENERATE_RPM=1 \
GENERATE_MSI=1 \
ENROLL_SECRET=6/EzU/+jPkxfTamWnRv1+IJsO4T9Etju \
FLEET_DESKTOP=1 \
FLEET_CERTIFICATE=1 \
./tools/tuf/test/main.sh
```
@@ -30,7 +31,10 @@ Separate `*_FLEET_URL` and `*_TUF_URL` variables are needed for each package to
E.g. The values shown above assume:
1. The script is executed on a macOS host.
2. Fleet server also running on the same macOS host.
3. Three VMs running on the macOS host where the access IP to host is `172.16.132.1`.
3. All VMs (and the macOS host itself) are configured to resolve `host.docker.internal` to the macOS host IP (by modifying their `hosts` file).
> PS: We use `host.docker.internal` because the testing certificate `./tools/osquery/fleet.crt`
> has such hostname (and `localhost`) defined as SANs.
# Add new updates
+11 -5
View File
@@ -1,6 +1,6 @@
#!/bin/bash
set -e
set -ex
# This script generates fleet-osquery packages for all supported platforms
# using the specified TUF server.
@@ -25,6 +25,12 @@ set -e
# ENROLL_SECRET: Fleet server enroll secret.
# ROOT_KEYS: TUF repository root keys.
# FLEET_DESKTOP: Whether to build with Fleet Desktop support.
# FLEET_CERTIFICATE: Whether to use a custom certificate bundle. If not set, then --insecure mode is used.
TLS_FLAG="--insecure"
if [ -n "$FLEET_CERTIFICATE" ]; then
TLS_FLAG="--fleet-certificate=./tools/osquery/fleet.crt"
fi
if [ -n "$GENERATE_PKG" ]; then
echo "Generating pkg..."
@@ -33,7 +39,7 @@ if [ -n "$GENERATE_PKG" ]; then
${FLEET_DESKTOP:+--fleet-desktop} \
--fleet-url=$PKG_FLEET_URL \
--enroll-secret=$ENROLL_SECRET \
--insecure \
${TLS_FLAG} \
--debug \
--update-roots="$ROOT_KEYS" \
--update-interval=10s \
@@ -48,7 +54,7 @@ if [ -n "$GENERATE_DEB" ]; then
${FLEET_DESKTOP:+--fleet-desktop} \
--fleet-url=$DEB_FLEET_URL \
--enroll-secret=$ENROLL_SECRET \
--insecure \
${TLS_FLAG} \
--debug \
--update-roots="$ROOT_KEYS" \
--update-interval=10s \
@@ -63,7 +69,7 @@ if [ -n "$GENERATE_RPM" ]; then
${FLEET_DESKTOP:+--fleet-desktop} \
--fleet-url=$RPM_FLEET_URL \
--enroll-secret=$ENROLL_SECRET \
--insecure \
${TLS_FLAG} \
--debug \
--update-roots="$ROOT_KEYS" \
--update-interval=10s \
@@ -78,7 +84,7 @@ if [ -n "$GENERATE_MSI" ]; then
${FLEET_DESKTOP:+--fleet-desktop} \
--fleet-url=$MSI_FLEET_URL \
--enroll-secret=$ENROLL_SECRET \
--insecure \
${TLS_FLAG} \
--debug \
--update-roots="$ROOT_KEYS" \
--update-interval=10s \