Client Certificate authentication issue and fix(?)

49 views
Skip to first unread message

Gregory Neagle

unread,
Feb 4, 2025, 2:12:01 PMFeb 4
to munki-dev, munki-discuss
If you use Client Certificate authentication with Munki (https://github.com/munki/munki/wiki/Using-Munki-With-SSL-Client-Certificates), please see


and


Since I cannot (easily) personally test any of this, I’m relying on people actually using Client Certificate authentication to test this proposed change and give us feedback.

-Greg

Gregory Neagle

unread,
Feb 6, 2025, 12:42:57 PMFeb 6
to munki-...@googlegroups.com, munki-dev
I’ve merged this change into the Munki6dev branch. If you use Client Certificate authentication, please test this change.

The easiest way to test might be to just grab a copy of this file https://github.com/munki/munki/blob/Munki6dev/code/client/munkilib/gurl.py and copy it to /usr/local/munki/munkilib/gurl.py on one or more test clients.

You could also build an entire new Munki tools package using `./code/tools/make_munki_mpkg_from_git.sh -b Munki6dev` from a git clone of the Munki repo. This is more complex, and will leave you with either an unsigned install of Munki, or (if you sign it yourself) a version not signed by the MacAdmins Open Source team.

-Greg

Gregory Neagle

unread,
Feb 6, 2025, 12:55:36 PMFeb 6
to munki-...@googlegroups.com, munki-dev
I’ll make testing even easier: I’ve attached a copy of the updated gurl.py file.

gurl.py
Reply all
Reply to author
Forward
0 new messages