Using ECC Workload
Certificates
(pilot-agent environmental variables)Using ECC Workload Certificates (pilot-agent environmental variables) Jacob Delgado / Aspen Mesh #IstioCon ECC workload certificates ● In various environments, the need for x509 certificates that that use Elliptical Curve Cryptography (ECC) is a requirement ● In Istio 1.6, support for workloads to use ECC certificates for mTLS in sidecar-to-sidecar communication was added ○ As of Istio 1.7.7+, 1.8.2+ and 1.9.0+ there is no longer the restriction that a plugged in CA certificate must use ECC cryptography (using ECDSA P-256) to use this feature ● Only ECDSA P-256 is supported #IstioCon pilot-agent0 码力 | 9 页 | 376.10 KB | 1 年前3
Using Istio to Build the Next 5G Platform©2021 Aspen Mesh. All rights reserved. Key Platform Requirements Multi-Vendor Real-Time (RAN) Workload Mobility Networking outside CNF Encryption & Authorization between CNFs 5 ©2021 Aspen Mesh. avoid escalated pod privileges ● Integrate with PKI minted Intermediate CA ● Enable ECC certificates ● Configure workload certificate TTLs ● Enable strict mutual TLS (mTLS) instead of auto ● Use dedicated architectural changes ● SPIFFE only certificates ● Configuring workload certificate TTLs ● RSA to ECC migration ● Missing www-authenticate header ● Tuning per-workload proxy concurrency ● Consuming Istio0 码力 | 18 页 | 3.79 MB | 1 年前3
FISCO BCOS 2.3.0 中文文档7d2833a1bde2a9899cfc4d0433d64b01d03e79927a a60a40507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0 若节点未启动,则直接启动节点,若节点已启动,可直接用脚本 reload_whitelist.sh刷新白名单配置即可(暂不支持动态刷新黑名单)。 查看节点连接 使用场景:公共CA 7d2833a1bde2a9899cfc4d0433d64b01d03e79927aa60a40 507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0 38158ef34eb2d58ce1d31c8f3ef9f1fa829d0eb8ed1657f4b2a3ebd3265d44b243c69 ffee0519c143dd67e9157 7d2833a1bde2a9899cfc4d0433d64b01d03e79927aa60a4 0507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0", "Topic": [] } ] } vim node0/config.ini [certificate_blacklist] ; crl.0 should0 码力 | 1227 页 | 10.79 MB | 1 年前3
FISCO BCOS 2.2.0 中文文档7d2833a1bde2a9899cfc4d0433d64b01d03e79927a a60a40507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0 若节点未启动,则直接启动节点,若节点已启动,可直接用脚本 reload_whitelist.sh刷新白名单配置即可(暂不支持动态刷新黑名单)。 查看节点连接 使用场景:公共CA 7d2833a1bde2a9899cfc4d0433d64b01d03e79927aa60a40 507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0 38158ef34eb2d58ce1d31c8f3ef9f1fa829d0eb8ed1657f4b2a3ebd3265d44b243c69 ffee0519c143dd67e9157 7d2833a1bde2a9899cfc4d0433d64b01d03e79927aa60a4 0507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0", "Topic": [] } ] } vim node0/config.ini [certificate_blacklist] ; crl.0 should0 码力 | 1156 页 | 10.03 MB | 1 年前3
FISCO BCOS 2.1.0 中文文档7d2833a1bde2a9899cfc4d0433d64b01d03e79927a a60a40507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0 # 若节点未启动 $ bash start.sh # 若节点已启动 $ cd scripts $ bash reload_whitelist.sh node_127.0.0.1_30300 7d2833a1bde2a9899cfc4d0433d64b01d03e79927aa60a40 507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0 38158ef34eb2d58ce1d31c8f3ef9f1fa829d0eb8ed1657f4b2a3ebd3265d44b243c69 ffee0519c143dd67e9157 7d2833a1bde2a9899cfc4d0433d64b01d03e79927aa60a4 0507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0", "Topic": [] } ] } vim node0/config.ini [certificate_blacklist] ; crl.0 should0 码力 | 1058 页 | 740.85 KB | 1 年前3
ubuntu server guidesecurity-smart-cards-ssh SSH 3 security-apparmor AppArmor 3 security-firewall Firewall 3 security-certificates Certificates 3 security-trust-store CA trust store 3 security-console Console 2 High Availability clear across the network. See LDAP with TLS for details on how to set up OpenLDAP with trusted SSL certificates. 153 Add the new configuration: sudo ldapadd -Q -Y EXTERNAL -H ldapi:/// -f consumer_simple_sync clear across the network. See LDAP with TLS for details on how to set up OpenLDAP with trusted SSL certificates. Add the new configuration: sudo ldapadd -Q -Y EXTERNAL -H ldapi:/// -f consumer_sync.ldif0 码力 | 486 页 | 3.33 MB | 1 年前3
FISCO BCOS 2.2.0 中文文档77d2833a1bde2a9899cfc4d0433d64b01d03e79927aa60a40507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0 若节点未启动,则直接启动节点,若节点已启动,可直接用脚本reload_whitelist.sh刷新白名单 配置即可(暂不支持动态刷新黑名单)。 # 若节点未启动 $ bash start 77d2833a1bde2a9899cfc4d0433d64b01d03e79927aa60a40507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0 38158ef34eb2d58ce1d31c8f3ef9f1fa829d0eb8ed1657f4b2a3ebd3265d44b243c69ffee0519c143dd67e91572 77d2833a1bde2a9899cfc4d0433d64b01d03e79927aa60a40507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0 ˓→", "Topic": [] } ] } 配 配 配置 置 置黑 黑 黑名 名 名单 单 单: : :node0拒 拒 拒绝 绝 绝node1的 的 的连 连 连接 接 接0 码力 | 418 页 | 6.51 MB | 1 年前3
FISCO BCOS 2.4.0 中文文档7d2833a1bde2a9899cfc4d0433d64b01d03e79927a a60a40507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0 若节点未启动,则直接启动节点,若节点已启动,可直接用脚本 reload_whitelist.sh刷新白名单配置即可(暂不支持动态刷新黑名单)。 查看节点连接 使用场景:公共CA 7d2833a1bde2a9899cfc4d0433d64b01d03e79927aa60a40 507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0 38158ef34eb2d58ce1d31c8f3ef9f1fa829d0eb8ed1657f4b2a3ebd3265d44b243c69 ffee0519c143dd67e9157 7d2833a1bde2a9899cfc4d0433d64b01d03e79927aa60a4 0507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0", "Topic": [] } ] } vim node0/config.ini [certificate_blacklist] ; crl.0 should0 码力 | 1314 页 | 11.21 MB | 1 年前3
FISCO BCOS 2.3.0 中文文档77d2833a1bde2a9899cfc4d0433d64b01d03e79927aa60a40507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0 若节点未启动,则直接启动节点,若节点已启动,可直接用脚本reload_whitelist.sh刷新白名单 配置即可(暂不支持动态刷新黑名单)。 # 若节点未启动 $ bash start 77d2833a1bde2a9899cfc4d0433d64b01d03e79927aa60a40507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0 38158ef34eb2d58ce1d31c8f3ef9f1fa829d0eb8ed1657f4b2a3ebd3265d44b243c69ffee0519c143dd67e91572 77d2833a1bde2a9899cfc4d0433d64b01d03e79927aa60a40507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0 ˓→", "Topic": [] } ] } 6.16. CA黑 黑 黑白 白 白名 名 名单 单 单 179 FISCO BCOS Documentation, 发 发 发布0 码力 | 442 页 | 7.23 MB | 1 年前3
FISCO BCOS 2.5.0 中文文档使用CFCA证书部署节点 使用前建议阅读证书说明 [https://fisco-bcos- documentation.readthedocs.io/zh_CN/latest/docs/manual/certificates.html] 购买前注意事项 普通版FISCO BCOS节点使用的节点证书算法为EC secp256k1曲线 国密版FISCO BCOS节点使用的节点证书算法为SM2 用户向CFCA购买前请确认签发算法是否正确 7d2833a1bde2a9899cfc4d0433d64b01d03e79927a a60a40507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0 若节点未启动,则直接启动节点,若节点已启动,可直接用脚本 reload_whitelist.sh刷新白名单配置即可(暂不支持动态刷新黑名单)。 查看节点连接 使用场景:公共CA 7d2833a1bde2a9899cfc4d0433d64b01d03e79927aa60a40 507c5739591b8122ee609cf5636e71b02ce5009f3b8361930ecc3a9abb0 38158ef34eb2d58ce1d31c8f3ef9f1fa829d0eb8ed1657f4b2a3ebd3265d44b243c69 ffee0519c143dd67e91570 码力 | 1456 页 | 13.35 MB | 1 年前3
共 1000 条
- 1
- 2
- 3
- 4
- 5
- 6
- 100













