Skip to content

Support mTLS authentication with KMIP servers. (resolves #982) - #993

Draft
ximon18 wants to merge 1 commit into
mainfrom
support-kmip-mtls-authentication
Draft

ximon18 wants to merge 1 commit into
mainfrom
support-kmip-mtls-authentication

Conversation

@ximon18

@ximon18 ximon18 commented Sep 15, 2026 •

Copy link
Copy Markdown
Member
  • Extend the Cascade CLI kmip add subcommand to take an optional SNI --server-name argument.
  • Extend the Cascade CLI kmip show subcommand to report the SNI server name value that is configured.
  • Extend the Cascade API HsmAddError type to also report missing client certificate or key, or I/O errors (if the server is unable to write the given certificate and key files to its filesystem).
  • Improve the user experience of adding a KMIP HSM via the CLI with additional feedback about what is happening.
  • Factor out Json type wrapping in the API kmip_server_add() function to a wrapper fn to improve readability.
  • Extend the API kmip_server_add() function to write given certificate and key files to the server filesystem on connection success.
  • Extend KMIP state file handling code to read and write mTLS related details.
  • Extend the key manager unit to read mTLS related details from the KMIP state file and to pass mTLS related KMIP command line arguments to the dnst keyset kmip add-server subcommand.
  • Factor KMIP credential file access out of the key manager unit to src/common/kmip_creds.rs.
  • Rename KmpClientCredentialsFile to KmipCredentialsManager and add fn save_mtls_data() to save mTLS certificate files to disk.
  • Factor KMIP mTLS certificate and key loading out of the zone signer unit into KmipCredentialsManager.
  • Update signer key loading to use KmipCredentialsManager::load_mtls_data().
  • Follow changed location in domain_kmip of export SyncConnPool type.

Note: Draft because it requires updated dnst, domain-kmip and kmip-protocol crates that haven't been released yet, and probably still needs more polishing and the new SNI server name command line argument still needs documenting.


  • If you are changing Rust code or integration tests (Cargo.*, crates/, etc/, integration-tests/, src/):

    • Did you run the integration tests with act through the act-wrapper (as described in TESTING.md)?
  • If you are adding/deleting man pages:

    • Did you update the man_pages config in doc/manual/source/conf.py?
    • Did you update the packaged man pages in the Cargo.toml?
    • Did you commit the freshly built man pages?

- Extend the Cascade CLI `kmip add` subcommand to take an optional SNI
`--server-name` argument.
- Extend the Cascade CLI `kmip show` subcommand to report the SNI server
name value that is configured.
- Extend the Cascade API HsmAddError type to also report missing client
certificate or key, or I/O errors (if the server is unable to write the
given certificate and key files to its filesystem).
- Improve the user experience of adding a KMIP HSM via the CLI with
additional feedback about what is happening.
- Factor out Json type wrapping in the API kmip_server_add() function to
a wrapper fn to improve readability.
- Extend the API kmip_server_add() function to write given certificate
and key files to the server filesystem on connection success.
- Extend KMIP state file handling code to read and write mTLS related
details.
- Extend the key manager unit to read mTLS related details from the KMIP
state file and to pass mTLS related KMIP command line arguments to the
`dnst keyset kmip add-server` subcommand.
- Factor KMIP credential file access out of the key manager unit to
src/common/kmip_creds.rs.
- Rename `KmpClientCredentialsFile` to `KmipCredentialsManager` and add
fn `save_mtls_data()` to save mTLS certificate files to disk.
- Factor KMIP mTLS certificate and key loading out of the zone signer
unit into `KmipCredentialsManager`.
- Update signer key loading to use
KmipCredentialsManager::load_mtls_data().
- Follow changed location in domain_kmip of export SyncConnPool type.
@ximon18 ximon18 added the enhancement New feature or request label Sep 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant