The mesh makes the bus's certificate itself
novox/hq 04-ISSUES/146. The foundation made it by running openssl inside the broker's image, which worked while the broker was one that carried it and stopped the day the bus changed: the new one has a shell and no openssl, so the step exited 127 and no mesh could be raised. No other image the bundle names has it either, so there was nothing to substitute. broker certificate --into <dir> writes the pair, --check is the step's verify. Self-signed on purpose — a host pins this server's exact certificate (ADR 0004) and at genesis there is no authority to ask — and made once, because a second certificate is one every host that pinned the first no longer believes. The key is written before the certificate, so an interruption never leaves something that looks finished.
This commit is contained in:
@@ -364,8 +364,11 @@ func identityCommand(ctx context.Context, args []string) error {
|
||||
}
|
||||
|
||||
func brokerCommand(args []string) error {
|
||||
if len(args) > 0 && args[0] == "certificate" {
|
||||
return busCertificate(args[1:])
|
||||
}
|
||||
if len(args) == 0 || args[0] != "show" {
|
||||
return errors.New("broker show")
|
||||
return errors.New("broker show | broker certificate [--check] --into <directory>")
|
||||
}
|
||||
known, err := broker.FromEnvironment()
|
||||
if errors.Is(err, broker.ErrNotConfigured) {
|
||||
|
||||
Reference in New Issue
Block a user