Reproduced 129 exactly on the workstation: genuine certificate from Mesh Internal CA, verify result: unable to get local issuer certificate (20), no mesh entry in the trust store. The public name on the same proxy verifies cleanly, which puts the fault where the report puts it.
What is in the way is not an assignment.ca-trust is merged in the catalogue and has never been registered with the mesh — 39 of 76 manifests are — so there is no module to assign. It dry-runs clean and needs no artifact built. The remaining work is register, assign, verify, and then exercise removal, which nothing has.
Two new issues found while reproducing it:
157 — every routed name is published with an .internal alias nothing serves. The hosts file says keycloak.novox.be.internal; the proxy serves keycloak.novox.internal and refuses the other by name. The first three names I tried came from the hosts file and failed with a TLS alert rather than a verification error, pointing at a regression that had not happened.
158 — the proxy re-logs all 52 routes every two seconds, 31 times a minute. The one line explaining 157 sat between two of them.
Also recorded because it was nearly filed as a defect and is not one: step-ca publishes roots: /roots.pem, which is PEM, so ca-trust's fetch and its refuse-a-non-certificate guard are both correct. Its other endpoint /roots returns JSON containing the text the guard greps for — the guard is sound only because of which path is published.
Checks: records, index, cycle all pass.
Reproduced 129 exactly on the workstation: genuine certificate from `Mesh Internal CA`, `verify result: unable to get local issuer certificate (20)`, no mesh entry in the trust store. The public name on the same proxy verifies cleanly, which puts the fault where the report puts it.
**What is in the way is not an assignment.** `ca-trust` is merged in the catalogue and has never been registered with the mesh — 39 of 76 manifests are — so there is no module to assign. It dry-runs clean and needs no artifact built. The remaining work is register, assign, verify, and then exercise removal, which nothing has.
Two new issues found while reproducing it:
- **157** — every routed name is published with an `.internal` alias nothing serves. The hosts file says `keycloak.novox.be.internal`; the proxy serves `keycloak.novox.internal` and refuses the other by name. The first three names I tried came from the hosts file and failed with a TLS alert rather than a verification error, pointing at a regression that had not happened.
- **158** — the proxy re-logs all 52 routes every two seconds, 31 times a minute. The one line explaining 157 sat between two of them.
Also recorded because it was nearly filed as a defect and is not one: step-ca publishes `roots: /roots.pem`, which is PEM, so ca-trust's fetch and its refuse-a-non-certificate guard are both correct. Its other endpoint `/roots` returns JSON containing the text the guard greps for — the guard is sound only because of which path is published.
Checks: records, index, cycle all pass.
The certificate is genuine, from Mesh Internal CA, and nothing on the
workstation trusts it — verbatim the error the report gives. The public
name on the same proxy verifies cleanly, which puts the fault exactly
where the report puts it.
What is in the way is not an assignment. `ca-trust` is merged in the
catalogue and has never been registered with the mesh — 39 of 76
manifests are — so there is no module to assign. It dry-runs clean and
needs no artifact built.
Two findings from reproducing it, both their own issues:
157 — every routed name is published with an `.internal` alias that
nothing serves. The hosts file says keycloak.novox.be.internal; the proxy
serves keycloak.novox.internal and refuses the other by name. The first
three names I tried came from the hosts file and failed with a TLS alert
rather than a verification error, which pointed at a regression that had
not happened.
158 — the proxy re-logs all 52 routes every two seconds, 31 times a
minute. The one line that explained 157 sat between two of them.
Also recorded, because it was nearly filed as a defect and is not one:
step-ca publishes roots as /roots.pem, which is PEM, so ca-trust's fetch
and its refuse-a-non-certificate guard are both right. Its other endpoint
/roots returns JSON that contains the text the guard greps for, so the
guard is sound only because of which path is published.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Reproduced 129 exactly on the workstation: genuine certificate from
Mesh Internal CA,verify result: unable to get local issuer certificate (20), no mesh entry in the trust store. The public name on the same proxy verifies cleanly, which puts the fault where the report puts it.What is in the way is not an assignment.
ca-trustis merged in the catalogue and has never been registered with the mesh — 39 of 76 manifests are — so there is no module to assign. It dry-runs clean and needs no artifact built. The remaining work is register, assign, verify, and then exercise removal, which nothing has.Two new issues found while reproducing it:
.internalalias nothing serves. The hosts file sayskeycloak.novox.be.internal; the proxy serveskeycloak.novox.internaland refuses the other by name. The first three names I tried came from the hosts file and failed with a TLS alert rather than a verification error, pointing at a regression that had not happened.Also recorded because it was nearly filed as a defect and is not one: step-ca publishes
roots: /roots.pem, which is PEM, so ca-trust's fetch and its refuse-a-non-certificate guard are both correct. Its other endpoint/rootsreturns JSON containing the text the guard greps for — the guard is sound only because of which path is published.Checks: records, index, cycle all pass.