Uploaded image for project: 'Artifactory Binary Repository'
  1. Artifactory Binary Repository
  2. RTFACT-17109

Circle of Trust does not work in Artifactory 5.7 and 5.8

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Normal
    • Resolution: Fixed
    • Affects Version/s: 5.7.0, 5.8.9
    • Fix Version/s: 5.9.0
    • Component/s: None
    • Labels:
      None
    • Regression:
      Yes

      Description

      Artifactory 5.7 introduced new and easier way to create Circle of Trust by using Trusted folder. However, the feature was not fully implemented till 5.9.

       

      The signature validation works, but the Token is rejected for a different reason - the Audience.

      This is although the Audience was set as jfrt@*, or even with the specific service_id of the second cluster, we get:

      "message" : "Token failed verification: audience"

        

      This issue was resolved as part of a larger change made to "Access Token’s Audience" in 5.9.

        Attachments

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              joshuah Joshua Han
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: