Skip to content

Enrollment process? #22

@sorenisanerd

Description

@sorenisanerd

What should the enrollment process look like?

How would the client authenticate itself to a supposed "enrollment service"? I.e. when an enrollment request comes in, how do we know it's legit?

Maybe it's fundamentally just a CSR that gets sent to the enrollment service. Organization policy can determine what kind and level of scrutiny to apply on the server side. Nodes can poll for a signed certificate.

How would it identify itself? What comprises its identity? machine-id?

Once enrolled, sd-sysupdate can pull the node's confext which can include hostname, network config, etc.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions