Jira (PUP-5450) Windows integration with local certificate store

1 view
Skip to first unread message

Ethan Brown (JIRA)

unread,
Oct 28, 2015, 7:46:02 PM10/28/15
to puppe...@googlegroups.com
Ethan Brown created an issue
 
Puppet / Task PUP-5450
Windows integration with local certificate store
Issue Type: Task Task
Assignee: Unassigned
Components: Windows
Created: 2015/10/28 4:45 PM
Priority: Normal Normal
Reporter: Ethan Brown

There have been a few customer reports of interest in leveraging the Windows certificate store for cert management, rather than storing the certs on disk.

For instance, it could be useful to import the CA into the local cert store, and it could be useful to use Windows tooling to generate / store the certs in the My store for the LocalMachine. This is more "Windows native" than writing PEM files to disk.

For instance, my Windows host has certs automatically created and placed in the My store like this:

C:\Users\Administrator> dir Cert:\LocalMachine\My
 
 
    Directory: Microsoft.PowerShell.Security\Certificate::LocalMachine\My
 
 
Thumbprint                                Subject
----------                                -------
99D0D1A4E577F39B19623A161289746233D56564  CN=WMSvc-VAGRANT-2008R2
5FBEE78476CCFC6758E817BC7316E8FDBD694259  CN=localhost

First class support of this would include some significant changes around:

  • Providing an option with the MSI install to use cert store instead of disk
  • Properly dealing with Puppet settings that have historically pointed to files on disk
  • Adding Windows specific code for cert management (likely using native APIs)
  • Updating relevant documentation
Add Comment Add Comment
 
This message was sent by Atlassian JIRA (v6.4.11#64026-sha1:78f6ec4)
Atlassian logo

Ethan Brown (JIRA)

unread,
Oct 28, 2015, 7:47:02 PM10/28/15
to puppe...@googlegroups.com
Ethan Brown updated an issue
 
Puppet / Story PUP-5450
Change By: Ethan Brown
Issue Type: Task Story

Rob Reynolds (JIRA)

unread,
Nov 20, 2015, 4:02:04 PM11/20/15
to puppe...@googlegroups.com
Rob Reynolds updated an issue
Change By: Rob Reynolds
CS Priority: Needs Priority
This message was sent by Atlassian JIRA (v6.4.12#64027-sha1:e3691cc)
Atlassian logo

Owen Rodabaugh (JIRA)

unread,
Dec 17, 2015, 6:34:07 PM12/17/15
to puppe...@googlegroups.com
Owen Rodabaugh updated an issue
Change By: Owen Rodabaugh
CS Priority: Needs Priority Reviewed

Kenaz Kwa (JIRA)

unread,
Aug 29, 2016, 7:47:20 PM8/29/16
to puppe...@googlegroups.com
Kenaz Kwa updated an issue
Change By: Kenaz Kwa
Team: Agent & Platform Support
This message was sent by Atlassian JIRA (v6.4.13#64028-sha1:b7939e9)
Atlassian logo

Josh Cooper (Jira)

unread,
Mar 5, 2020, 1:52:03 AM3/5/20
to puppe...@googlegroups.com
Josh Cooper commented on Story PUP-5450
 
Re: Windows integration with local certificate store

It would not be too difficult to write a CertProvider that retrieved keys and certs from the local Windows store, but given that this ticket hasn't been updated in more than 2 years, I'm closing it. Please reopen if this is still a concern.

This message was sent by Atlassian Jira (v8.5.2#805002-sha1:a66f935)
Atlassian logo
Reply all
Reply to author
Forward
0 new messages