route-proxy: an empty ACME_CA_BUNDLE means the system trust store
Piece A of ADR 0056 (selectable issuer). A provider that serves an empty root —
public-acme, whose root already ships in the OS trust store — leaves route-proxy's
CA bundle file existing but empty, because the mesh writes it unconditionally from
${bound:acme-ca:root}. Read that as "trust the system roots", the same as an unset
bundle, instead of failing with "holds no certificate this can trust". A bundle
that holds bytes but no parseable certificate is still refused.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -203,6 +203,13 @@ func run() error {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("ACME_CA_BUNDLE names %s and it cannot be read: %w", bundle, err)
|
return fmt.Errorf("ACME_CA_BUNDLE names %s and it cannot be read: %w", bundle, err)
|
||||||
}
|
}
|
||||||
|
// An empty bundle means the issuer's root is already in the system trust store — a public
|
||||||
|
// authority whose root ships with the OS, pointed at by a provider that serves an empty
|
||||||
|
// root (novox/hq ADR 0056). The mesh always writes the bundle file, so it exists and holds
|
||||||
|
// nothing; that is the signal to fall back to the system roots, the same as if nothing had
|
||||||
|
// named a bundle at all. A file that holds bytes but no certificate is still a
|
||||||
|
// misconfiguration and is refused, because there the operator meant to trust something.
|
||||||
|
if strings.TrimSpace(string(pem)) != "" {
|
||||||
pool := x509.NewCertPool()
|
pool := x509.NewCertPool()
|
||||||
if !pool.AppendCertsFromPEM(pem) {
|
if !pool.AppendCertsFromPEM(pem) {
|
||||||
return fmt.Errorf("%s holds no certificate this can trust", bundle)
|
return fmt.Errorf("%s holds no certificate this can trust", bundle)
|
||||||
@@ -212,6 +219,7 @@ func run() error {
|
|||||||
Transport: &http.Transport{TLSClientConfig: &tls.Config{RootCAs: pool}},
|
Transport: &http.Transport{TLSClientConfig: &tls.Config{RootCAs: pool}},
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
}
|
||||||
manager := &autocert.Manager{
|
manager := &autocert.Manager{
|
||||||
Cache: autocert.DirCache(cache),
|
Cache: autocert.DirCache(cache),
|
||||||
Prompt: autocert.AcceptTOS,
|
Prompt: autocert.AcceptTOS,
|
||||||
|
|||||||
Reference in New Issue
Block a user