The proxy's jail reads a refused name as well as a refused certificate (hq ADR 0179) #226

Merged
mesh-admin merged 2 commits from fix/the-proxys-jail-reads-both-refusals into main 2026-10-02 15:23:48 +00:00
Contributor

The pattern ended at the line's end, which only the certificate refusal does; a request for a name the mesh does not serve carries trailing text and would never have matched. Caught against the live lines before the jail counted anything.

The pattern ended at the line's end, which only the certificate refusal does; a request for a name the mesh does not serve carries trailing text and would never have matched. Caught against the live lines before the jail counted anything.
mesh-admin added 1 commit 2026-10-02 15:21:04 +00:00
The pattern ended at the line's end, which only the certificate refusal does; a request for
an unserved name carries trailing text and never matched. Caught against the live lines
before the jail counted anything (hq ADR 0179).
jschoubben added 1 commit 2026-10-02 15:23:43 +00:00
fail2ban expands <HOST> to a named group, so two in one pattern is a duplicate group name and
the daemon refuses to start at all -- every jail on the machine, not just this one. Two patterns,
one <HOST> each: the certificate refused for an unserved name, and the request refused for one.
Caught live on the control node (hq ADR 0179).
mesh-admin merged commit 419d92e810 into main 2026-10-02 15:23:48 +00:00
mesh-admin deleted branch fix/the-proxys-jail-reads-both-refusals 2026-10-02 15:23:48 +00:00
Sign in to join this conversation.
No Reviewers
No labels
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#226