step-ca: stop offering acme-ca, so public names are certified by public-acme
step-ca and public-acme both offered acme-ca on novox, and route-proxy's pin names a node, not a module — so which one certified the public names depended on provider order. After the controller restart on 2026-10-03 it came out as step-ca, and every public site served a certificate no browser trusts. step-ca's own names are already certified through internal-acme-ca; acme-ca is the public authority's alone.
This commit is contained in:
@@ -5,20 +5,12 @@
|
||||
"container-runtime"
|
||||
],
|
||||
"provides": [
|
||||
{
|
||||
"name": "acme-ca",
|
||||
"scope": "mesh"
|
||||
},
|
||||
{
|
||||
"name": "internal-acme-ca",
|
||||
"scope": "mesh"
|
||||
}
|
||||
],
|
||||
"serves": {
|
||||
"acme-ca": {
|
||||
"path": "/acme/acme/directory",
|
||||
"roots": "/roots.pem"
|
||||
},
|
||||
"internal-acme-ca": {
|
||||
"path": "/acme/acme/directory",
|
||||
"roots": "/roots.pem"
|
||||
|
||||
Reference in New Issue
Block a user