Wildcard-free certificates for network address domains
Generating an access point certificate based on a graph that defines relationships between an access point and at least one domain is described. Relationship data describing how data is to be routed between an access point and domains is received by a certificate management system. The certificate management system generates a graph representing an access point and associated domains as nodes, with edges connecting various nodes to model relationships between the access point and the associated domains. Based on the graph, a certificate is generated that individually lists each domain associated with the access point and includes information describing data routing for the domain via the access point. The certificate excludes wildcard entries that represent multiple domains via a single entry. The certificate is used to control data communication traffic via the access point and is updated responsive to changes in in domain relationship data for the access point.
1 . A method comprising:
generating, by a computing device, a graph that defines relationships between a network address and a plurality of different domains, the graph comprising a plurality of nodes that each represent a corresponding one of the plurality of different domains or the network address;
generating, by the computing device, a first certificate for the network address based on the graph, the first certificate listing each of the plurality of nodes in the graph that identify corresponding ones of the plurality of different domains as separate certificate entries;
controlling access to the network address using the first certificate;
detecting, by the computing device, a change to at least one of the relationships between the network address and one or more of the plurality of different domains;
generating, by the computing device, a modified graph based on the change to the at least one of the relationships;
generating, by the computing device, a second certificate for the network address based on the modified graph, the second certificate listing individual nodes in the modified graph as separate certificate entries; and
controlling access to the network address using the second certificate instead of the first certificate.
2 . The method of claim 1 , wherein generating the first certificate is performed without including a single certificate entry that comprises a character indicating multiple subdomains as being valid.
3 . The method of claim 1 , wherein generating the second certificate is performed without including a single certificate entry that comprises a character indicating multiple subdomains as being valid.
4 . The method of claim 1 , wherein the network address is served by multiple providers that comprise a first provider hosted by an entity and a second provider hosted by a content delivery network that is different than the entity, wherein the first provider is represented in the graph by a first node and the second provider is represented in the graph by a second node.
5 . The method of claim 4 , wherein each of the plurality of nodes that represent the plurality of different domains is connected by a link to the first node or the second node in the graph.
6 . The method of claim 1 , wherein the network address is a virtual internet protocol address configured for access by at least one of a physical network interface or a device.
7 . The method of claim 1 , wherein detecting the change to the at least one of the relationships is performed based on data received from a listener at the network address that describes at least one configuration change for one or more of the plurality of different domains.
8 . The method of claim 1 , wherein detecting the change to the at least one of the relationships is performed in response to detecting expiration of the first certificate.
9 . A system comprising:
at least one processor; and
a computer-readable storage medium storing instructions that are executable by the at least one processor to perform operations comprising:
generating a graph that defines relationships between a network address and at least one domain, the graph comprising a plurality of nodes that each represent a corresponding domain of the at least one domain or the network address;
generating a first certificate for the network address using the graph, the first certificate listing each of the plurality of nodes in the graph that identify corresponding ones of the at least one domain as separate certificate entries;
responsive to a change to a relationship between the network address and the at least one domain, generating a modified graph based on the change to the relationship between the network address and the at least one domain; and
generating a second certificate for the network address using the modified graph, the second certificate listing individual nodes in the modified graph as separate certificate entries.
10 . The system of claim 9 , wherein generating the first certificate is performed without including a single certificate entry that comprises a character indicating multiple subdomains as being valid.
11 . The system of claim 9 , wherein generating the second certificate is performed without including a single certificate entry that comprises a character indicating multiple subdomains as being valid.
12 . The system of claim 9 , wherein the network address is served by multiple providers that comprise a first provider hosted by a first entity and a second provider hosted by a second entity that is different than the first entity, wherein the first provider is represented in the graph by a first node and the second provider is represented in the graph by a second node.
13 . The system of claim 12 , wherein the graph further comprises at least one node that represents a corresponding one of the at least one domain associated with the first entity or the second entity, wherein each node of the at least one node is connected by a link to the first node or the second node in the graph.
14 . The system of claim 9 , wherein the network address is a virtual internet protocol address configured for access by at least one of a physical network interface or a device.
15 . The system of claim 9 , the operations further comprising detecting the change to the relationship based on data, generated by a listener at the network address, that describes at least one configuration change for the at least one domain.
16 . The system of claim 9 , the operations further comprising detecting the change to the relationship responsive to an expiration of the first certificate.
17 . The system of claim 9 , the operations further comprising controlling access to the network address using the second certificate instead of the first certificate.
18 . A method comprising:
receiving, at an access point, a certificate generated from a graph that defines relationships between the access point and a plurality of domains, each of the plurality of domains being represented as a separate node in the graph and being listed in the certificate as a separate certificate entry;
receiving, from a device, a request to access data via at least one of the plurality of domains; and
responsive to authenticating the device using the certificate, controlling data transfer between the at least one of the plurality of domains and the device based on the relationships between the access point and the at least one of the plurality of domains.
19 . The method of claim 18 , wherein the certificate does not include a single certificate entry that comprises a character indicating multiple subdomains as being valid.
20 . The method of claim 18 , wherein the access point is a virtual internet protocol address configured for access by at least one of a physical network interface or a device.