The certificate bed reads the names a certificate is for from its alternative names
Pebble, like the public authority it stands in for, leaves the subject empty; the bed read the subject and refused a valid certificate.
This commit is contained in:
@@ -194,12 +194,16 @@ test("a public name is served with a certificate the mesh did not issue", {
|
||||
assert.match(served.out, /hello/);
|
||||
|
||||
// And it is the authority's certificate, not something self-signed that happens to work.
|
||||
const issuer = await must(
|
||||
// The issuer, and the names the certificate is FOR — its alternative names, not its subject:
|
||||
// Pebble, like the public authority it stands in for, leaves the subject empty and puts the
|
||||
// name in the alternative names alone. The first version of this read the subject and refused
|
||||
// a valid certificate.
|
||||
const issued = await must(
|
||||
`echo | openssl s_client -connect ${NAME}:443 -servername ${NAME} 2>/dev/null ` +
|
||||
`| openssl x509 -noout -issuer -subject`,
|
||||
`| openssl x509 -noout -issuer -ext subjectAltName`,
|
||||
);
|
||||
assert.match(issuer, /Pebble/i, `the certificate was not issued by the ACME server:\n${issuer}`);
|
||||
assert.match(issuer, new RegExp(NAME), `the certificate is not for the name asked for:\n${issuer}`);
|
||||
assert.match(issued, /Pebble/i, `the certificate was not issued by the ACME server:\n${issued}`);
|
||||
assert.match(issued, new RegExp(`DNS:${NAME.replace(".", "\\.")}`), `the certificate is not for the name asked for:\n${issued}`);
|
||||
});
|
||||
|
||||
test("the same order against a second authority: the catalogue's own certificate authority", {
|
||||
@@ -247,12 +251,12 @@ test("the same order against a second authority: the catalogue's own certificate
|
||||
`── the proxy tried:\n${proxyLog}\n── the authority heard:\n${authority}\n`);
|
||||
}
|
||||
assert.match(served.out, /hello/);
|
||||
const issuer = await must(
|
||||
const issued = await must(
|
||||
`echo | openssl s_client -connect ${NAME}:443 -servername ${NAME} 2>/dev/null ` +
|
||||
`| openssl x509 -noout -issuer -subject`,
|
||||
`| openssl x509 -noout -issuer -ext subjectAltName`,
|
||||
);
|
||||
assert.match(issuer, /Lab CA/, `the certificate was not issued by the second authority:\n${issuer}`);
|
||||
assert.match(issuer, new RegExp(NAME), `the certificate is not for the name asked for:\n${issuer}`);
|
||||
assert.match(issued, /Lab CA/, `the certificate was not issued by the second authority:\n${issued}`);
|
||||
assert.match(issued, new RegExp(`DNS:${NAME.replace(".", "\\.")}`), `the certificate is not for the name asked for:\n${issued}`);
|
||||
});
|
||||
|
||||
test("no certificate is ordered for a name the mesh does not route", {
|
||||
|
||||
Reference in New Issue
Block a user