step-ca: stop offering acme-ca, so public names are certified by public-acme
step-ca and public-acme both offered acme-ca on novox, and route-proxy's pin names a node, not a module — so which one certified the public names depended on provider order. After the controller restart on 2026-10-03 it came out as step-ca, and every public site served a certificate no browser trusts. step-ca's own names are already certified through internal-acme-ca; acme-ca is the public authority's alone.
This commit is contained in:
@@ -5,20 +5,12 @@
|
|||||||
"container-runtime"
|
"container-runtime"
|
||||||
],
|
],
|
||||||
"provides": [
|
"provides": [
|
||||||
{
|
|
||||||
"name": "acme-ca",
|
|
||||||
"scope": "mesh"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"name": "internal-acme-ca",
|
"name": "internal-acme-ca",
|
||||||
"scope": "mesh"
|
"scope": "mesh"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"serves": {
|
"serves": {
|
||||||
"acme-ca": {
|
|
||||||
"path": "/acme/acme/directory",
|
|
||||||
"roots": "/roots.pem"
|
|
||||||
},
|
|
||||||
"internal-acme-ca": {
|
"internal-acme-ca": {
|
||||||
"path": "/acme/acme/directory",
|
"path": "/acme/acme/directory",
|
||||||
"roots": "/roots.pem"
|
"roots": "/roots.pem"
|
||||||
|
|||||||
Reference in New Issue
Block a user