Issue 129 is resolved: a workstation trusts the mesh, and stops when told to
Registered ca-trust from the catalogue — it was merged and had never been registered, which is why "assign it to one machine" had no module to name — assigned it to the workstation, and verified. Verified in the form ADR 0147 prescribes, against the authority's own API so the handshake needs nothing else in the mesh to be right: 200, issuer Mesh Internal CA, Verify return code 0. Four routed internal names verify too, and `git ls-remote https://…` works, which is the consequence the report named. Removal exercised for the first time. Unassign and push removes the anchor, empties the trust store of the mesh's authority, and returns the plain client to the original error; assigning again restores it. That is the half 0147 claimed and nothing had shown. One thing it found that is not in the module: removal works only because the host removes the service before the script. Stopping the unit is what deletes the certificate and refreshes the bundles, and it needs the script to still exist. The symmetry rests on an ordering nothing states. 0147's "written, and not yet run" now carries a progressive insight saying it has run, where, and that it ran on one machine of four.
This commit is contained in:
@@ -113,6 +113,34 @@ the authority it was bound to, checked in the control plane's own test suite —
|
||||
that verified anything. That is a weaker thing than the paragraph above describes, and it stays
|
||||
written this way until the bed runs.
|
||||
|
||||
> **Progressive insight — 2026-09-30. It has now been run, on the live mesh rather than in the bed.**
|
||||
> The paragraph above said nothing had verified anything, and something has. The module was registered
|
||||
> from the catalogue, assigned to a workstation, and checked in the form this section prescribes — the
|
||||
> authority's own API, so the handshake needs nothing else in the mesh to be right:
|
||||
>
|
||||
> ```
|
||||
> $ curl -sS -o /dev/null -w '%{http_code}' https://<the authority>:9000/health
|
||||
> 200
|
||||
> subject=CN=Step Online CA
|
||||
> issuer=O=Mesh Internal CA, CN=Mesh Internal CA Intermediate CA
|
||||
> Verify return code: 0 (ok)
|
||||
> ```
|
||||
>
|
||||
> **Both halves.** Unassigning and pushing removed the anchor, emptied the trust store of the mesh's
|
||||
> authority, and returned the plain client to *unable to get local issuer certificate* — then assigning
|
||||
> again restored it. The negative half is what distinguishes the anchor working from something else
|
||||
> having trusted it, and it is the half nothing had ever exercised.
|
||||
>
|
||||
> **One thing this found that is not in the module.** The removal only works because the *host* removes
|
||||
> the service before the script: stopping the unit is what deletes the certificate and refreshes the
|
||||
> bundles, and it needs the script it calls to still exist. Nothing in the module states that ordering;
|
||||
> the symmetry this record claims rests on it.
|
||||
>
|
||||
> Run on the live mesh because that is where a change is verified now
|
||||
> ([ADR 0149](0149-the-live-mesh-is-the-test-bed.md)), and the bed still cannot raise a foundation. The
|
||||
> evidence is [issue 129](../04-ISSUES/129-nothing-makes-a-machine-trust-the-meshs-authority/02-resolution.md).
|
||||
> It ran on **one** machine; three others still trust nothing of the mesh's.
|
||||
|
||||
## Consequences
|
||||
|
||||
The predecessor's authority can be retired from a machine once this module is assigned to it,
|
||||
|
||||
Reference in New Issue
Block a user