1.4.0 (2021-06-30)


  • Extended CertGuard.ca_certificate to accept a cert-bundle in addition to a single cert. #8783

1.3.0 (2021-05-19)

No significant changes.

1.2.0 (2021-03-17)

No significant changes.

1.1.0 (2020-12-14)

  • Adding version-info to
  • Making pulp-certguard compatible with pulpcore 3.9.

1.0.3 (2020-09-25)

No significant changes. A compatibility release used to declare compatibility up to pulpcore==3.8.

1.0.2 (2020-08-18)

No significant changes.

1.0.1 (2020-07-20)


  • Making pulp-certguard compatible with pulpcore 3.5 #7177

1.0.0 (2020-07-01)

No significant changes.

0.1.0rc5 (2020-05-22)


  • Add support for non-urlencoded certificates to allow Apache < 2.6.10 reverse proxies to also work. #6574


  • RHSMCertGuard now only checks for authorized URLs in the client cert against the Distribution.base_path and disincludes the settings.CONTENT_PATH_PREFIX, e.g. /pulp/content/ #6694

Improved Documentation

  • Adds docs on configuring Apache 2.6.10+ and < 2.6.10 docs, which need different configs. #6574
  • Adds documentation on RHSM path checking with examples. Also adds a debugging section on inspecting RHSM certificates with the rct command. #6694
  • Adds debugging documentation on how users can enable, use, and interpret the debugging logging. #6744

0.1.0rc4 (2020-04-22)


  • Adds RHSMCertGuard which offers both content protection and path-based entitlement checking. #4664
  • Make repositories “typed”. Repositories now live at a detail endpoint. Sync is performed by POSTing to {repo_href}/sync/ remote={remote_href}. #5625
  • X509CertGuard.ca_certificate is now stored in the database and not on the filesystem. #6352

Improved Documentation

  • Adds documentation on how authorization checking works and that there are two types of Certguards now. #4664
  • Move documentation from to sphinx site to show on #6298
  • Total rewrite of the documentation with tested reverse proxy examples, X509 Cert Guard usage, and RHSM Cert Guard usage. #6445
  • Adds notes to docs that to use RHSMCertGuard you have to install rhsm Python module. #6546

Deprecations and Removals

  • Renames the SSL_CLIENT_CERTIFICATE to be X-CLIENT-CERT. #4891

  • Change _id, _created, _last_updated, _href to pulp_id, pulp_created, pulp_last_updated, pulp_href #5457

  • Sync is no longer available at the {remote_href}/sync/ repository={repo_href} endpoint. #5625

  • Migrations had to be regenerated from scratch due to a backwards incompatible change where X509ContentGuard.ca_certificate is now stored in the database and not on the filesystem. Users who have already run migrations will need to drop the RHSMCertGuard and X509CertGuard tables manually from their databases, reapply migrations, and re-create their CertGuard objects.

    Also the submission of the client cert to the content app occurs via the X-CLIENT-CERT header, and is expected to be urlencoded. #6352

0.1.0rc2 (2019-09-20)

Improved Documentation



Initial release!