WBS: 3.6 done, and the certificate constraint it surfaced

The NATS client has no checkServerIdentity hook, so pinning no longer makes
the name check redundant — the bus's certificate must carry a SAN matching
the address nodes dial.
This commit is contained in:
2026-09-26 23:29:56 +02:00
parent d2ed3152d3
commit 80456981be
+13 -1
View File
@@ -232,7 +232,19 @@ pays for itself furthest away.
- [ ] 3.3 the fixtures restated on NATS, and the capability each implementation claims
- [ ] 3.4 the controller's link on NATS
- [ ] 3.5 the host's link on NATS — mirroring, still importing nothing
- [ ] 3.6 the tool runtime's client on NATS, behind the unchanged sdk contract
- [x] 3.6 the tool runtime's client on NATS, behind the unchanged sdk contract — round-tripped
against a real server: a tool answered across two connections, a throwing handler reaching
the caller as an error rather than a timeout, an event delivered once with its key, body,
node and event id intact. Ships beside the AMQP client and is selected at the rollout,
because steps 1 to 4 leave every node on AMQP.
**A constraint it surfaced, recorded where somebody issuing a certificate will look.** The
AMQP client pinned the exact certificate and switched hostname verification off, which is
sound because a fingerprint is stronger than a name. The NATS client exposes no equivalent
hook — its TLS options are PEM strings with no verify callback — so the pin still happens
before dialling and the library's own name check happens beside it. **The bus's certificate
must carry a subject-alternative name matching the address nodes dial it by**, or the
connection is refused by a library error rather than by anything the mesh says.
- [ ] 3.7 the sdk's three stale comments, and nothing else in it
- [ ] 3.8 **the declaration model** of [design 29](29-what-a-module-declares.md): local names
derived to subjects, the three namespaces, permissions computed from a declaration, and a