11418 Commits

Author SHA1 Message Date
Michel Vocks
488be87f67
Fix error handling during client TLS config setup (#8025) 2019-12-18 11:22:15 +01:00
Becca Petrin
39455f38a8
Avoid potential panic in LDAP client (#8047)
* fix potential panic

* add comment

* vendor the ldap update

* use localhost in test
2019-12-17 16:33:59 -08:00
Sam Salisbury
0715c8b77b ci: update to go 1.12.14 2019-12-17 19:26:04 +00:00
Jim Kalafut
f6991b25f6
changelog++ 2019-12-17 10:52:41 -08:00
Jim Kalafut
a8de99b4c0 Fix identity token panic during invalidation (#8015)
* Fix identity token crash during invalidation

* Check for nil namespace

* Fix test

* Add nil check test

* Check OIDC cache errors
2019-12-17 10:43:38 -08:00
Becca Petrin
b2efef5c2f
run go mod tidy (#8041) 2019-12-17 10:37:58 -08:00
Darshana Sivakumar
592a0db6b1 Update telemetry.html.md to add a note on replication metrics (#8036)
Added a note on replication metrics.
2019-12-17 09:20:31 -08:00
Jim Kalafut
83c7cecfd5
Update README 2019-12-17 05:24:23 -08:00
Joel Thompson
d725f97b30 Bump aws-sdk-go to v1.25.41 (#7458)
This is in support of #7450 and #7924
2019-12-16 16:43:00 -08:00
Noelle Daley
c772e6b4c6
update serialize-javascript to fix security vulnerability (#8029) 2019-12-16 15:14:52 -08:00
Noelle Daley
0be9054fe1
Update CHANGELOG.md 2019-12-16 14:37:07 -08:00
Noelle Daley
24bfade659
overwrite bulma bug that crashes safari (#8023) 2019-12-16 13:30:35 -08:00
Jim Kalafut
5e3ba14f6b
changelog++ 2019-12-16 12:05:31 -08:00
Becca Petrin
2a5d57b974
changelog++ 2019-12-16 11:20:49 -08:00
ncabatoff
7d25514057
changelog++ 2019-12-16 09:42:43 -05:00
ncabatoff
a14ce331ea
changelog++ 2019-12-16 09:41:46 -05:00
ncabatoff
7ba8339c9c
Fix panic when creating batch tokens for role that doesn't exist. (#8021) 2019-12-16 09:31:32 -05:00
Michel Vocks
9d968accf0
Docs: Add missing KV V2 version argument to API docs (#8018) 2019-12-16 09:35:48 +01:00
Michel Vocks
2c21ef4df6
Fix SRV lookup if address scheme is known (#8016) 2019-12-16 09:34:40 +01:00
Noelle Daley
fc58f669e8
Update CHANGELOG.md 2019-12-13 15:26:12 -08:00
Noelle Daley
c5efd226ed
Ui/fix demoting status menu (#7997)
* fix bug where users couldn't click on update primary

* don't show status menu items when cluster isSecondary since those links don't work

* show the mode of replication in the status menu

* do not show server header in status menu when the contents are empty

* show Disaster Recovery instead of 'DR'

* do not show http metrics in status menu unless user is authenticated

* fix typo so icons in status menu show
2019-12-13 15:23:17 -08:00
Jim Kalafut
dd2fe725fc
changelog++ 2019-12-13 11:21:19 -08:00
Michael Golowka OR 1=1); DROP TABLE users; --
abeb24c113
Split helm docs to multiple pages under Helm Chart (#8011)
* Split helm docs to multiple pages under Helm Chart

- Fixed some minor formatting typos
- Added a note at the beginning of most of the pages indicating
incompatibility with helm 3

* Remove duplicate examples
2019-12-13 12:09:34 -07:00
Jeff Mitchell
bfb63d7220 changelog++ 2019-12-12 14:41:51 -05:00
Jeff Mitchell
cee00b4445 changelog++ 2019-12-12 14:41:09 -05:00
Jim Kalafut
3712dfa32e
changelog++ 2019-12-11 14:09:54 -08:00
Becca Petrin
92febcd203
add sts_region to aws auth api docs (#8001) 2019-12-11 13:45:39 -08:00
ncabatoff
03e61fc368
Update KMIP docs re supported operations. (#8008) 2019-12-11 16:22:25 -05:00
Michel Vocks
e1b6971e1c Add accept header check for prometheus mime type (#7958)
* Add accept header check for prometheus mime type

* Fix small header filter bug. Add test
2019-12-11 11:59:19 -08:00
Becca Petrin
73fd8f314f
Add Kerberos SPNEGO auth plugin (#7908) 2019-12-11 11:18:37 -08:00
Becca Petrin
f259edcceb
Kerberos docs (#7993) 2019-12-11 11:16:36 -08:00
chrismatteson
921f5efed4 Removed typo space (#8007) 2019-12-11 11:01:28 -08:00
catsby
e523f1feec
remove redundant check and clarify code comment 2019-12-11 10:16:09 -06:00
Clint
3b4313095b
Changelog++ 2019-12-11 09:33:39 -06:00
Clint
3f62e7f30b
Transit: error when restoring to a name that looks like a path (#7998)
* Add test to verify #7663

* Validate name in transit key restore to not be a path
2019-12-11 09:32:22 -06:00
ncabatoff
dd3dcd7069
Handle otherName SANs in CSRs (#6163)
If a CSR contains a SAN of type otherName, encoded in UTF-8, and the signing role specifies use_csr_sans, the otherName SAN will be included in the signed cert's SAN extension.

Allow single star in allowed_other_sans to match any OtherName.  Update documentation to clarify globbing behaviour.
2019-12-11 10:16:44 -05:00
Becca Petrin
6b2d5ac3dc
Add an sts_region parameter to the AWS auth engine's client config (#7922) 2019-12-10 16:02:04 -08:00
Calvin Leung Huang
ab0be03486
changelog++ 2019-12-10 10:53:41 -08:00
Calvin Leung Huang
8d0b7b150c
plugin: fix panic on router.MatchingSystemView if backend is nil (#7991)
* plugin: fix panic on router.MatchingSystemView if backend is nil

* correctly determine the plugin binary file in the directory

* docs: simplify plugin file removal
2019-12-10 10:48:30 -08:00
Calvin Leung Huang
a3af0e476f
docs: add section on upgrading plugins (#7984)
* docs: add section on upgrading plugins

* docs: move plugin upgrade to its own guides page

* docs: reword step 4

* docs: add page to sidebar
2019-12-10 10:15:01 -08:00
Clint
805a0bc9b4 revert a change introduced 13dbb3aac (#7979) 2019-12-07 18:01:11 -08:00
Jeff Mitchell
412751ba50 changelog++ 2019-12-06 16:17:22 -05:00
Steve Wills
13dbb3aac3 Fix UI build in fresh repo (#7865)
Fixes #7863
2019-12-06 12:58:40 -06:00
Chris Hoffman
a1a407f76b
changelog++ 2019-12-06 12:24:03 -05:00
Chris Hoffman
5c68d61aa5
changelog++ 2019-12-06 12:18:26 -05:00
Mike Jarmy
df01a4307d
Introduce optional service_registration stanza (#7887)
* move ServiceDiscovery into methods

* add ServiceDiscoveryFactory

* add serviceDiscovery field to vault.Core

* refactor ConsulServiceDiscovery into separate struct

* cleanup

* revert accidental change to go.mod

* cleanup

* get rid of un-needed struct tags in vault.CoreConfig

* add service_discovery parser

* add ServiceDiscovery to config

* cleanup

* cleanup

* add test for ConfigServiceDiscovery to Core

* unit testing for config service_discovery stanza

* cleanup

* get rid of un-needed redirect_addr stuff in service_discovery stanza

* improve test suite

* cleanup

* clean up test a bit

* create docs for service_discovery

* check if service_discovery is configured, but storage does not support HA

* tinker with test

* tinker with test

* tweak docs

* move ServiceDiscovery into its own package

* tweak a variable name

* fix comment

* rename service_discovery to service_registration

* tweak service_registration config

* Revert "tweak service_registration config"

This reverts commit 5509920a8ab4c5a216468f262fc07c98121dce35.

* simplify naming

* refactor into ./serviceregistration/consul
2019-12-06 09:46:39 -05:00
Jason O'Donnell
47cffd09f9 Add int64 pointerutil (#7973) 2019-12-05 14:02:36 -08:00
Chris Hoffman
1645b20127
if storing the certificate, always generate/sign the certificate on the primary (#7904) 2019-12-05 13:50:28 -05:00
Jim Kalafut
fd1542d048
changelog++ 2019-12-04 06:21:46 -08:00
Jim Kalafut
55bba5537c
Fix S3 configurable path handling (#7966)
Also remove some incorrect skipping of the S3 test.

Fixes #7362
2019-12-04 06:18:45 -08:00