Jira (PUP-10261) X-Hub-Signature check

6 views
Skip to first unread message

Dirk (JIRA)

unread,
Jan 31, 2020, 8:07:04 AM1/31/20
to puppe...@googlegroups.com
Dirk created an issue
 
Puppet / New Feature PUP-10261
X-Hub-Signature check
Issue Type: New Feature New Feature
Assignee: Unassigned
Components: Networking
Created: 2020/01/31 5:06 AM
Labels: github
Priority: Normal Normal
Reporter: Dirk

Dear puppet team,

we got a request from the AXA security team to check with you if it would be possible to enhance the puppet enterprise code manage with a verification that an received webhook was send by the AXA enterprise Github:

"<...>, there are some ways to ensure the hook is coming from github:
https://developer.github.com/enterprise/2.17/webhooks/
https://developer.github.com/webhooks/securing/

  • github is sending some headers X-Github-xxx and a user-agent, so a first check is possible here
  • A header is called X-Hub-Signature, containing a hash (HMAC hex digest) based on a secret. Some tools are able to check this signature to validate <...>

Based on the Puppet version you’re using, can you contact the Puppet Support Team and ask them if there’s a way to implement the X-Hub-Signature check when they receive a payload from github ?"

If you need any further information please contact me.

Best regards and many thanks in advance,
Dirk

Add Comment Add Comment
 
This message was sent by Atlassian JIRA (v7.7.1#77002-sha1:e75ca93)
Atlassian logo

Patrick Grant (JIRA)

unread,
Jan 31, 2020, 8:12:03 AM1/31/20
to puppe...@googlegroups.com
Patrick Grant updated an issue
Change By: Patrick Grant
Zendesk Ticket IDs: 37914

Rob Braden (JIRA)

unread,
Feb 3, 2020, 12:51:05 PM2/3/20
to puppe...@googlegroups.com
Rob Braden updated an issue
Change By: Rob Braden
Team: Froyo

Josh Cooper (Jira)

unread,
Jul 30, 2020, 12:52:03 PM7/30/20
to puppe...@googlegroups.com
Josh Cooper commented on New Feature PUP-10261
 
Re: X-Hub-Signature check

It sounds like this is a feature request for Puppet Enterprise Code Manager? Assuming yes, I'm going to move this ticket to that project.

This message was sent by Atlassian Jira (v8.5.2#805002-sha1:a66f935)
Atlassian logo
Reply all
Reply to author
Forward
0 new messages