From 0778f8f0ae28015cc4b23b7d61760611a85002e3 Mon Sep 17 00:00:00 2001 From: jochen Date: Sat, 3 Oct 2026 10:54:43 +0200 Subject: [PATCH] step-ca: stop offering acme-ca, so public names are certified by public-acme MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit step-ca and public-acme both offered acme-ca on novox, and route-proxy's pin names a node, not a module — so which one certified the public names depended on provider order. After the controller restart on 2026-10-03 it came out as step-ca, and every public site served a certificate no browser trusts. step-ca's own names are already certified through internal-acme-ca; acme-ca is the public authority's alone. --- modules/step-ca/module.json | 8 -------- 1 file changed, 8 deletions(-) diff --git a/modules/step-ca/module.json b/modules/step-ca/module.json index ff35a7e..cbdd57f 100644 --- a/modules/step-ca/module.json +++ b/modules/step-ca/module.json @@ -5,20 +5,12 @@ "container-runtime" ], "provides": [ - { - "name": "acme-ca", - "scope": "mesh" - }, { "name": "internal-acme-ca", "scope": "mesh" } ], "serves": { - "acme-ca": { - "path": "/acme/acme/directory", - "roots": "/roots.pem" - }, "internal-acme-ca": { "path": "/acme/acme/directory", "roots": "/roots.pem" -- 2.54.0