Skip to content

Conditionally skip username check within certificate principals#21

Open
ArmaanT wants to merge 1 commit into
uber:masterfrom
ArmaanT:fix/skip-username-check
Open

Conditionally skip username check within certificate principals#21
ArmaanT wants to merge 1 commit into
uber:masterfrom
ArmaanT:fix/skip-username-check

Conversation

@ArmaanT

@ArmaanT ArmaanT commented Aug 18, 2021

Copy link
Copy Markdown

This PR removes the requirement that a username must appear within a certificate's list of principals so long as an explicit set of valid principals is defined. This change was made so that the call to c.CheckCert on line 166 will verify the certificate, but explicitly exclude checking principals because pam-ussh verifies principals later in the code.

This change is related to #15.

Skip checking if the username exists within the SSH certificiate
principals if a manual set of valid principals is defined
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant