diff --git a/03-DESIGN/01-to-be/28-building-the-bus.md b/03-DESIGN/01-to-be/28-building-the-bus.md index 7e48f4b..4495fce 100644 --- a/03-DESIGN/01-to-be/28-building-the-bus.md +++ b/03-DESIGN/01-to-be/28-building-the-bus.md @@ -232,7 +232,19 @@ pays for itself furthest away. - [ ] 3.3 the fixtures restated on NATS, and the capability each implementation claims - [ ] 3.4 the controller's link on NATS - [ ] 3.5 the host's link on NATS — mirroring, still importing nothing -- [ ] 3.6 the tool runtime's client on NATS, behind the unchanged sdk contract +- [x] 3.6 the tool runtime's client on NATS, behind the unchanged sdk contract — round-tripped + against a real server: a tool answered across two connections, a throwing handler reaching + the caller as an error rather than a timeout, an event delivered once with its key, body, + node and event id intact. Ships beside the AMQP client and is selected at the rollout, + because steps 1 to 4 leave every node on AMQP. + + **A constraint it surfaced, recorded where somebody issuing a certificate will look.** The + AMQP client pinned the exact certificate and switched hostname verification off, which is + sound because a fingerprint is stronger than a name. The NATS client exposes no equivalent + hook — its TLS options are PEM strings with no verify callback — so the pin still happens + before dialling and the library's own name check happens beside it. **The bus's certificate + must carry a subject-alternative name matching the address nodes dial it by**, or the + connection is refused by a library error rather than by anything the mesh says. - [ ] 3.7 the sdk's three stale comments, and nothing else in it - [ ] 3.8 **the declaration model** of [design 29](29-what-a-module-declares.md): local names derived to subjects, the three namespaces, permissions computed from a declaration, and a