Issue 129 is live and reproduced, and needs three steps rather than one #198

Merged
jschoubben merged 1 commits from issue/129-and-what-reproducing-it-found into main 2026-09-29 23:30:48 +00:00
Owner

Reproduced 129 exactly on the workstation: genuine certificate from Mesh Internal CA, verify result: unable to get local issuer certificate (20), no mesh entry in the trust store. The public name on the same proxy verifies cleanly, which puts the fault where the report puts it.

What is in the way is not an assignment. ca-trust is merged in the catalogue and has never been registered with the mesh — 39 of 76 manifests are — so there is no module to assign. It dry-runs clean and needs no artifact built. The remaining work is register, assign, verify, and then exercise removal, which nothing has.

Two new issues found while reproducing it:

  • 157 — every routed name is published with an .internal alias nothing serves. The hosts file says keycloak.novox.be.internal; the proxy serves keycloak.novox.internal and refuses the other by name. The first three names I tried came from the hosts file and failed with a TLS alert rather than a verification error, pointing at a regression that had not happened.
  • 158 — the proxy re-logs all 52 routes every two seconds, 31 times a minute. The one line explaining 157 sat between two of them.

Also recorded because it was nearly filed as a defect and is not one: step-ca publishes roots: /roots.pem, which is PEM, so ca-trust's fetch and its refuse-a-non-certificate guard are both correct. Its other endpoint /roots returns JSON containing the text the guard greps for — the guard is sound only because of which path is published.

Checks: records, index, cycle all pass.

Reproduced 129 exactly on the workstation: genuine certificate from `Mesh Internal CA`, `verify result: unable to get local issuer certificate (20)`, no mesh entry in the trust store. The public name on the same proxy verifies cleanly, which puts the fault where the report puts it. **What is in the way is not an assignment.** `ca-trust` is merged in the catalogue and has never been registered with the mesh — 39 of 76 manifests are — so there is no module to assign. It dry-runs clean and needs no artifact built. The remaining work is register, assign, verify, and then exercise removal, which nothing has. Two new issues found while reproducing it: - **157** — every routed name is published with an `.internal` alias nothing serves. The hosts file says `keycloak.novox.be.internal`; the proxy serves `keycloak.novox.internal` and refuses the other by name. The first three names I tried came from the hosts file and failed with a TLS alert rather than a verification error, pointing at a regression that had not happened. - **158** — the proxy re-logs all 52 routes every two seconds, 31 times a minute. The one line explaining 157 sat between two of them. Also recorded because it was nearly filed as a defect and is not one: step-ca publishes `roots: /roots.pem`, which is PEM, so ca-trust's fetch and its refuse-a-non-certificate guard are both correct. Its other endpoint `/roots` returns JSON containing the text the guard greps for — the guard is sound only because of which path is published. Checks: records, index, cycle all pass.
jschoubben added 1 commit 2026-09-29 23:30:37 +00:00
The certificate is genuine, from Mesh Internal CA, and nothing on the
workstation trusts it — verbatim the error the report gives. The public
name on the same proxy verifies cleanly, which puts the fault exactly
where the report puts it.

What is in the way is not an assignment. `ca-trust` is merged in the
catalogue and has never been registered with the mesh — 39 of 76
manifests are — so there is no module to assign. It dry-runs clean and
needs no artifact built.

Two findings from reproducing it, both their own issues:

157 — every routed name is published with an `.internal` alias that
nothing serves. The hosts file says keycloak.novox.be.internal; the proxy
serves keycloak.novox.internal and refuses the other by name. The first
three names I tried came from the hosts file and failed with a TLS alert
rather than a verification error, which pointed at a regression that had
not happened.

158 — the proxy re-logs all 52 routes every two seconds, 31 times a
minute. The one line that explained 157 sat between two of them.

Also recorded, because it was nearly filed as a defect and is not one:
step-ca publishes roots as /roots.pem, which is PEM, so ca-trust's fetch
and its refuse-a-non-certificate guard are both right. Its other endpoint
/roots returns JSON that contains the text the guard greps for, so the
guard is sound only because of which path is published.
jschoubben merged commit e1b74810a8 into main 2026-09-29 23:30:48 +00:00
jschoubben deleted branch issue/129-and-what-reproducing-it-found 2026-09-29 23:30:48 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#198