-
Notifications
You must be signed in to change notification settings - Fork 500
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[DOC] Missing documentation for security features #433
Comments
@hardik-k-shah: Do you have more information on the following:
|
Below PRs has a description about how to use these APIs.
Let me know if these helps. |
Hi Chris, with all of the progress we've mad with security, can you check to see if we've covered any of these points? Thanks. |
Hi @hardik-k-shah, Do you now if these items have been documented? |
Security has been moved to a new team. I'll follow up with them and get this prioritized. |
I can pick this one up with @leanneeliatra |
Signed-off-by: AntonEliatra <anton.rubin@eliatra.com>
Signed-off-by: AntonEliatra <anton.rubin@eliatra.com>
Signed-off-by: AntonEliatra <anton.rubin@eliatra.com>
I'm taking care of |
Thanks, @AntonEliatra! Here are the doc PRs:
Please let me know if something is missing. |
"Hot re-loadable nodes_dn/ certificate domain name" is already documented here I spoke with @natebower and we don't think there is anything further needed here, but we can discuss further if you feel additional details are necessary |
For this part of this ticket: Audit logging configuration is hot reloadable and there are APIs and UI both available. The original work that was done is contained in these two PRs:
This comment is to log that the supporting updates to the documentation, to support the above 2 PR code changes, has already been completed. The information below points to the locations in the security docs where these updates have been added.
|
Hi Heather,
I have some updates for this issue and the final 2 remaining items in my name.
* 2) Hot re-loadable Audit logging.
After investigation, I have found this is already documented in the docs with new additions to the documentation 8 months and 11 months ago. I have added a comment #433 (comment) on the ticket showing where the updates to the docs can be found.
* 4) CRUD for default/reserved configuration: #6927 #6927
The changes related to this PR were quite heavy, I have an idea of what was carried out but I had been hoping to speak to an original reviewer of the work to discuss and ensure I had the right picture. I will proceed with what I understand of the changes and we can hopefully get the opinion of Hardik Shaw or another original contributor once my updates to the documentation is ready.
|
* adding separate certificates section #433 Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Update tls.md Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Update tls.md Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Apply suggestions from code review Co-authored-by: Naarcha-AWS <97990722+Naarcha-AWS@users.noreply.github.com> Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Update tls.md Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Update tls.md Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Apply suggestions from code review Signed-off-by: Naarcha-AWS <97990722+Naarcha-AWS@users.noreply.github.com> * Apply suggestions from code review Signed-off-by: Naarcha-AWS <97990722+Naarcha-AWS@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: Nathan Bower <nbower@amazon.com> Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> --------- Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> Signed-off-by: Naarcha-AWS <97990722+Naarcha-AWS@users.noreply.github.com> Co-authored-by: Heather Halter <HDHALTER@AMAZON.COM> Co-authored-by: Naarcha-AWS <97990722+Naarcha-AWS@users.noreply.github.com> Co-authored-by: Nathan Bower <nbower@amazon.com>
* adding separate certificates section #433 Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Update tls.md Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Update tls.md Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Apply suggestions from code review Co-authored-by: Naarcha-AWS <97990722+Naarcha-AWS@users.noreply.github.com> Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Update tls.md Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Update tls.md Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Apply suggestions from code review Signed-off-by: Naarcha-AWS <97990722+Naarcha-AWS@users.noreply.github.com> * Apply suggestions from code review Signed-off-by: Naarcha-AWS <97990722+Naarcha-AWS@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: Nathan Bower <nbower@amazon.com> Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> --------- Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> Signed-off-by: Naarcha-AWS <97990722+Naarcha-AWS@users.noreply.github.com> Co-authored-by: Heather Halter <HDHALTER@AMAZON.COM> Co-authored-by: Naarcha-AWS <97990722+Naarcha-AWS@users.noreply.github.com> Co-authored-by: Nathan Bower <nbower@amazon.com> (cherry picked from commit 77fb6ce) Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
* adding hot reload TLS certificate section #433 Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * fixing issues on hot reload #433 Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Update tls.md Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Apply suggestions from code review Co-authored-by: Naarcha-AWS <97990722+Naarcha-AWS@users.noreply.github.com> Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Apply suggestions from code review Co-authored-by: Nathan Bower <nbower@amazon.com> Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Update tls.md Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> --------- Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> Co-authored-by: Naarcha-AWS <97990722+Naarcha-AWS@users.noreply.github.com> Co-authored-by: Nathan Bower <nbower@amazon.com>
* adding hot reload TLS certificate section #433 Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * fixing issues on hot reload #433 Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Update tls.md Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Apply suggestions from code review Co-authored-by: Naarcha-AWS <97990722+Naarcha-AWS@users.noreply.github.com> Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Apply suggestions from code review Co-authored-by: Nathan Bower <nbower@amazon.com> Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> * Update tls.md Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> --------- Signed-off-by: AntonEliatra <anton.rubin@eliatra.com> Co-authored-by: Naarcha-AWS <97990722+Naarcha-AWS@users.noreply.github.com> Co-authored-by: Nathan Bower <nbower@amazon.com> (cherry picked from commit fa38567) Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Everything has been addressed except admin/superadmin roles which is being addressed in #7069 and has a separate issue assigned #4646. Thanks, @leanneeliatra ! |
Add documentation for below security features.
The text was updated successfully, but these errors were encountered: