Surface the existing "Certificates" card on the host details page for Windows hosts, with parity to macOS. Requires osquery 5.23.1 or higher. <!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #31294 Demo video: https://www.youtube.com/watch?v=kGRp-YtnnJc Docs: https://github.com/fleetdm/fleet/pull/48493/changes # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. ## Testing - [x] Added/updated automated tests - [x] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually ## Database migrations - [x] Checked schema for all modified table for columns that will auto-update timestamps during migration. - [x] Confirmed that updating the timestamps is acceptable, and will not cause unwanted side effects. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **New Features** * Windows host certificates now display on the host details page (gated by minimum agent/osquery version), including scope (**System** vs **User**) and improved scope-aware certificates list details. * **Bug Fixes** * Certificate table labeling and help text are now platform-appropriate (with “Keychain” renamed to “Scope”). * Windows certificate reconciliation is more resilient, preserving certificates for scopes not observed during a collection run and preventing row collapsing when ids repeat across scopes. * **Tests** * Expanded coverage for Windows/malformed DN parsing and scope-aware reconciliation. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
3 lines
179 B
Plaintext
3 lines
179 B
Plaintext
- Added the certificates list to the host details page for Windows hosts, showing each certificate's scope (System or
|
|
User). This requires osquery 5.23.1 or higher on the host.
|