-
Notifications
You must be signed in to change notification settings - Fork 2
Open
Description
What should the enrollment process look like?
How would the client authenticate itself to a supposed "enrollment service"? I.e. when an enrollment request comes in, how do we know it's legit?
Maybe it's fundamentally just a CSR that gets sent to the enrollment service. Organization policy can determine what kind and level of scrutiny to apply on the server side. Nodes can poll for a signed certificate.
How would it identify itself? What comprises its identity? machine-id?
Once enrolled, sd-sysupdate can pull the node's confext which can include hostname, network config, etc.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels