route-proxy: internal names are certified by the mesh's own authority
Two name spaces, two authorities (08-connectivity §2): a public name is certified by a public CA, an internal one by the mesh's own. step-ca now offers that second seat as internal-acme-ca beside its existing acme-ca, and route-proxy requires both — the server dispatches by which authority may certify the name at all, so an .internal alias stops being plain-HTTP only without ever asking a public CA for a name it cannot validate.
This commit is contained in:
@@ -8,12 +8,20 @@
|
||||
{
|
||||
"name": "acme-ca",
|
||||
"scope": "mesh"
|
||||
},
|
||||
{
|
||||
"name": "internal-acme-ca",
|
||||
"scope": "mesh"
|
||||
}
|
||||
],
|
||||
"serves": {
|
||||
"acme-ca": {
|
||||
"path": "/acme/acme/directory",
|
||||
"roots": "/roots.pem"
|
||||
},
|
||||
"internal-acme-ca": {
|
||||
"path": "/acme/acme/directory",
|
||||
"roots": "/roots.pem"
|
||||
}
|
||||
},
|
||||
"listens": [
|
||||
|
||||
Reference in New Issue
Block a user