The routing record is 0066, not 0056
0056 is 'the authority is the control plane, not a database'. A citation pointing at the wrong decision is worse than none: it reads as corroboration. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -211,7 +211,7 @@ func run() error {
|
||||
root = read
|
||||
// An empty bundle means the issuer's root is already in the system trust store — a public
|
||||
// authority whose root ships with the OS, pointed at by a provider that serves an empty
|
||||
// root (novox/hq ADR 0056). The mesh always writes the bundle file, so it exists and holds
|
||||
// root (novox/hq ADR 0066). The mesh always writes the bundle file, so it exists and holds
|
||||
// nothing; that is the signal to fall back to the system roots, the same as if nothing had
|
||||
// named a bundle at all. A file that holds bytes but no certificate is still a
|
||||
// misconfiguration and is refused, because there the operator meant to trust something.
|
||||
@@ -257,7 +257,7 @@ func run() error {
|
||||
// forThisAuthority is where one ACME authority's account and certificates are kept.
|
||||
//
|
||||
// **A cached ACME account belongs to the authority that issued it, and nothing in the cache says
|
||||
// so** (novox/hq ADR 0056). autocert keeps its account key at one fixed name — `acme_account+key` —
|
||||
// so** (novox/hq ADR 0066). autocert keeps its account key at one fixed name — `acme_account+key` —
|
||||
// in whatever directory it is given, and reuses it for ever. That is right while the authority stays
|
||||
// the same and silently wrong the moment it does not: an internal CA that is re-initialised is a new
|
||||
// authority with a new root, it has never heard of the account in the cache, and every attempt to
|
||||
|
||||
Reference in New Issue
Block a user