Skip to content

[X.509] Backward Compatibility #896

@averevki

Description

@averevki

Summary

Verify that existing AuthConfig mTLS behavior is not broken by the new x509.source field changes.

Priority: High — Should be implemented early.

The existing tests use TLSEnvoy gateway with hostname.client(verify=envoy_authority, cert=valid_cert) pattern. The new tests use KuadrantGateway with XFCC-based cert extraction. These are fundamentally different gateway setups, so new tests will likely be needed rather than adapting existing ones.

Setup

  • AuthPolicy without source field (legacy behavior — expects cert in attributes.source.certificate)

Tests

  • Verify existing behavior is not broken

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    Test caseNew test caseenhancementImprovement to existing test

    Type

    No type

    Projects

    Status

    🆕 New

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions