SSL certificate configuration in Hashicorp Vault

Viewed 4279

I have recently started using Vault for storing my api keys and secrets. I am trying to configure it to use HTTPS using ssl certificates and I believe I have done all the steps.

But when i try to launch the url from browser I get a pop-up asking for selecting a certificate. (Image attached). I don't know what is wrong here. When i click Cancel it works fine and loads the page correctly but I shouldn't get getting that pop-up.

My vault config -

storage "file" {
  path = "/vault/store/data"
}

listener "tcp" {
  address     = "vault.systems:8200"
  tls_disable = 0
  tls_cert_file = "/app/vault/cert/vault.systems.cer"
  tls_key_file = "/app/vault/cert/vault.systems.key"
}

api_addr = "https://vault.systems:8200"

ui = true

Also I have placed the root certificate under /etc/pki/ca-trust/source/anchors/ and updated the ca-trust.

Everything works fine as below is the response from the curl -

user@vault-server-1$ curl -XGET https://vault.systems:8200/v1/sys/health
{"initialized":true,"sealed":true,"standby":true,"performance_standby":false,"replication_performance_mode":"unknown","replication_dr_mode":"unknown","server_time_utc":1604577030,"version":"1.5.3"}

enter image description here

2 Answers

Fixing this issue involves making a tweak to your TCP listener's config stanza.  For the TCP listener, Vault includes a parameter called tls_disable_client_certs which allows you to toggle this functionality.  By default, the value of this parameter is false and Vault will request client certificates when available.  

To disable this behavior, simply update the TCP listener stanza in your Vault configuration file to include the following line.

tls_disable_client_certs = "true"

Below is an example of how this would look in a Vault configuration file.

...  
listener "tcp" {  
  address = "0.0.0.0:8200"  
  tls_cert_file = "/opt/vault/tls/vault-cert.crt"  
  tls_key_file = "/opt/vault/tls/vault-key.key"  
  tls_client_ca_file = "/opt/vault/tls/vault-ca.crt"  
  tls_disable_client_certs = "true"  
}  
...

If you'd like to read more, I wrote a knowledge base article detailing how to handle this.

To disable the client certificate verification, use:

tls_disable_client_certs = true

Or, the following check can be used to bypass the popup:

tls_require_and_verify_client_cert = false
Related