45 Commits

Author SHA1 Message Date
Mike Reeves
c0968d3843 Update signing_policies.conf 2023-11-20 15:57:29 -05:00
Mike Reeves
57612c69fe Update signing_policies.conf 2023-11-20 15:11:50 -05:00
Mike Reeves
94accb0e8c Update signing_policies.conf 2023-11-20 15:09:13 -05:00
m0duspwnens
2aa19b78da dont remove ca-certificates.crt 2022-01-26 11:27:35 -05:00
m0duspwnens
a43fb293fc remove role logic 2022-01-26 10:26:52 -05:00
m0duspwnens
8aa002b82e add states to remove ca and ssl keys and certs and call them during reinstall. 2022-01-26 09:33:19 -05:00
m0duspwnens
a46a740170 account for salt 3004 adding new chars to random.get_str 2022-01-14 17:23:29 -05:00
m0duspwnens
2a5b4ef276 add mine function to signing_policies.conf. no longer need to check if mine in ca during manager install 2021-12-28 15:19:06 -05:00
m0duspwnens
2405de4b82 fix require 2021-12-28 11:00:35 -05:00
m0duspwnens
f2adcf4ca5 ensure /etc/pki is created and simplify ca logic for non manager in ssl state 2021-12-28 10:41:57 -05:00
m0duspwnens
f93c6146f5 docker binds requires 2021-10-21 15:24:55 -04:00
m0duspwnens
1d8e065902 fix salt retries - https://github.com/Security-Onion-Solutions/securityonion/issues/3948 2021-04-22 08:35:50 -04:00
m0duspwnens
e6ecd609cc change timeouts to 30s 2021-01-29 13:44:11 -05:00
m0duspwnens
0936dbdb1c add timeouts and retries to ca/ssl states 2021-01-28 11:40:31 -05:00
m0duspwnens
b693373d8d change how we allow or disallow states to be run https://github.com/Security-Onion-Solutions/securityonion/issues/2679 2021-01-20 15:09:53 -05:00
m0duspwnens
09cc8ae1fb fail the state if it isnt in top 2020-09-09 16:48:50 -04:00
m0duspwnens
a229ae82ce only allow state to run if it is in top for the node 2020-09-02 16:15:52 -04:00
m0duspwnens
1f3ceb50da add replace: False to get rid of warning, eventhough it doesntt. bug report submitted on saltstack gh. 2020-08-10 13:04:19 -04:00
m0duspwnens
c00b452f8d change module.run for ca state 2020-07-28 15:10:16 -04:00
m0duspwnens
7606cc0ad0 changes to ssl state for salt 3001 2020-07-27 15:51:31 -04:00
m0duspwnens
b2e7a4221c master to manager for ssl signing policy 2020-07-09 17:19:17 -04:00
m0duspwnens
5ca3ecf4bd fix reference to master grain 2020-07-09 15:42:39 -04:00
m0duspwnens
3cf31e2460 https://github.com/Security-Onion-Solutions/securityonion/issues/404 2020-07-09 11:27:06 -04:00
Mike Reeves
be5f4b04c6 Fix SSL Perms 2020-07-06 17:21:23 -04:00
Jason Ertel
97d127218a fix: stop updating salt mine - this is an attempt to sort out why the CA intermittently disappears from the mine 2020-06-15 17:40:58 -04:00
m0duspwnens
939ab918b4 update states using module.run - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/106 2019-11-07 17:31:06 -05:00
Mike Reeves
0f5c0373c5 SSL Issue 79 - Remove extensions from filebeat cert 2019-10-23 15:27:31 -04:00
Mike Reeves
3ecb6a7c3f SSL Issue 79 - Add extended type to all certs 2019-10-21 17:55:06 -04:00
Mike Reeves
06261b0b9a SSL Issue 79 - Add extended type to all certs 2019-10-21 17:54:09 -04:00
Mike Reeves
792cc7d4c4 SSL Issue 79 - Reduce valid time 2019-10-21 17:04:18 -04:00
Mike Reeves
53f7fcd07c Fleet Module - SSL additions 2018-12-05 15:54:43 -05:00
Mike Reeves
39602f3ef8 InfluxDB Module - Add Support for influxdb 2018-11-17 16:24:23 -05:00
Mike Reeves
3fa9d0cd55 CA Module - Trying to fix SSL keys 2018-10-11 09:02:20 -04:00
Mike Reeves
a42c14f1af CA Module - Formatting is important 2018-10-11 08:46:08 -04:00
Mike Reeves
8a25da1ee9 Reverse Proxy - The Big Commit 2018-10-10 21:24:24 -04:00
Mike Reeves
188ce9dd89 CA Module - remove new syntax 2018-08-29 11:00:35 -04:00
Mike Reeves
d31592e59c CA Module - Update module.run syntax 2018-08-29 10:46:15 -04:00
Mike Reeves
3870e3cb95 SSL Module - It's Working 2018-07-17 12:52:04 -04:00
Mike Reeves
4046f5fc00 SSL Module - Change registry settings 2018-07-17 12:34:22 -04:00
Mike Reeves
5137866826 SSL Module - Allow the CA to sign client certs 2018-07-16 12:44:28 -04:00
Mike Reeves
853b6768c4 SSL Module - Allow the CA to sign client certs 2018-07-16 12:36:16 -04:00
Mike Reeves
8070bd718e SSL Setup - Changed CN to master host 2018-06-05 16:20:16 -04:00
Mike Reeves
652a0d0592 Setup - Add peer config to the master config 2018-05-24 11:23:05 -04:00
Mike Reeves
9311031931 SSL and CA Modules - Create a private key 2018-05-24 10:45:17 -04:00
Mike Reeves
ee2d5b37b4 SSL and CA Modules - Add base 2018-05-23 16:56:44 -04:00