You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Note: This story has expanded beyond its initial scope and is now primarily comprised of leftover work from previous Android stories. It can be split into multiple stories if needed.
Goal
User story
As an IT admin,
I want to deploy certificates from my certificate authority (CA) to Android hosts via UI/API and confirm that they're deployed by visiting the Host details page
so that I can connect my end users to the corporate Wi-Fi or VPN.
Roadmap item
📄 Deploy certificates for Wi-Fi and VPN on personal mobile devices (iOS/iPadOS, Android) and company-owned Windows, & Linux computers
Document that in order to install certificates, if the host is enrolled prior to 4.78, it must be re-enrolled
Database schema migrations: Yes
This is a premium only feature: Yes
ℹ️ Please read this issue carefully and understand it. Pay special attention to UI wireframes, especially "dev notes".
QA
Risk assessment
Requires load testing: No (because we don't have the infrastructure)
Risk level: Low (customer requires support for 1000 devices initially)
Test plan
Make sure to go through the list and consider all events that might be related to this story, so we catch edge cases earlier.
UPDATE: Since Dogfood has 4.79 RC, please do part of the QA on Dogfood. At the very least, try the happy path flow.
UI
Make sure a new page for certificates is available in Fleet Premium at /controls/os-settings/certificates, and in Fleet Free, we show "Premium" message.
Verify that the user can add a certificate by filling out the form in the Add certificate modal.
Verify that the user sees a validation error on the name input field if using unsupported characters or name is too long.
Verify that the user sees a validation error if provides name that is used by existing certificate on the same team.
Verify that the user can't create a certificate if all fields aren't present.
Make sure that once the certificate is added, the user can see the certificate name, CA name, and the uploaded at timestamp on /controls/os-settings/certificates page.
This should be tested a few times on a fully loaded loadtest instance because it uses replica DB. Dev note: @jacobshandling Are we using the old read after write pattern here? We know it fails if the replication lag is large. Should we try to not actively use this pattern going forward?
Verify that when the user adds a certificate, the number of pending hosts in the summary section above the certificate list is increased by the number of hosts in that team. It should be increased right after the upload.
Verify that once the certificate is added to the team, on the host details page (OS settings modal), the certificate is listed with the name that the user provided and pending status.
Verify that when the certificate is actually installed on the Android host, the status is verified.
Verify that a certificate template can't be saved if we use a non-existing Fleet variable (e.g., $FLEET_VAR_BOZO)
Verify that the status on the host details page is failed if the user provides an IdP variable that is not available for that host.
Make sure that the user can delete a certificate on the /controls/os-settings/certificates page, and that the user sees a confirmation modal.
Verify that when the user deletes a certificate, the number of pending hosts in the summary section above the certificate list is increased by the number of hosts in that team. It should be increased right after the upload.
Verify that once the certificate is deleted from the team, on the host details page (OS settings modal), the certificate is listed with the name that the user provided and pending status. (Removing enforcement)
Verify that the certificate is actually deleted on the host when it's deleted in Fleet UI/API.
Verify that if certificate is uninstalled, it's removed from the list.
Verify that activities are generated when the user adds or deletes the certificate.
Make sure that the Certificates page under Settings > Integrations is renamed to "Certificate authorities"
API
Verify that the user can add a certificate via POST /api/v1/fleet/certificates
Verify that the user can list added certificates via GET /api/v1/fleet/certificates
Verify that the user can get a certificate's details via GET /api/v1/fleet/certificates/:id
Verify that the user can delete a certificate via DELETE /api/v1/fleet/certificates/:id
Verify that when a user is adding a certificate via POST /api/v1/fleet/certificates, Fleet validates the name and returns an error if the user specifies non-supported characters, or a too-long name, or a duplicate name.
Note: This story has expanded beyond its initial scope and is now primarily comprised of leftover work from previous Android stories. It can be split into multiple stories if needed.
Goal
Roadmap item
📄 Deploy certificates for Wi-Fi and VPN on personal mobile devices (iOS/iPadOS, Android) and company-owned Windows, & Linux computers
Original requests
#13420
Resources
None.
Changes
Product
certificatesarray underhost.mdm.os_settings. It should includeoperation_typecontrols.android_settings.certificatesas part of thegitops generatecommandEngineering
QA
Risk assessment
Test plan
UPDATE: Since Dogfood has 4.79 RC, please do part of the QA on Dogfood. At the very least, try the happy path flow.
UI
/controls/os-settings/certificates, and in Fleet Free, we show "Premium" message./controls/os-settings/certificatespage.pendingstatus.$FLEET_VAR_BOZO)failedif the user provides an IdP variable that is not available for that host./controls/os-settings/certificatespage, and that the user sees a confirmation modal.pendingstatus. (Removing enforcement)API
POST /api/v1/fleet/certificatesGET /api/v1/fleet/certificatesGET /api/v1/fleet/certificates/:idDELETE /api/v1/fleet/certificates/:idPOST /api/v1/fleet/certificates, Fleet validates the name and returns an error if the user specifies non-supported characters, or a too-long name, or a duplicate name./fleet/certificatesvalidation missing #37761operation_typeandstatusare returned in each certificate object underhost.mdm.certificates(GET /host/:idendpoint).Scenarios
GitOps
Testing notes
Confirmation