Skip to content

Conversation

@CBenoit
Copy link
Member

@CBenoit CBenoit commented Jun 20, 2025

Certificates missing the auth extended key usage, or missing a subject alternative name are now rejected:

  • immediately fail on startup for certificates from filesystem, and
  • fail on certificate resolution for system certificate store.

Issue: DGW-286

CBenoit added 2 commits June 21, 2025 02:30
When the certificate is missing the auth extended key usage, or does not
have any subject alternative name:
- fail on startup for certificates from filesystem, and
- fail on certificate resolution for system certificate store.

Issue: DGW-286
@CBenoit CBenoit enabled auto-merge (squash) June 21, 2025 14:12
@CBenoit CBenoit changed the title feat(dgw): fail-fast on improper certificate for TLS fix(dgw)!: fail-fast on improper certificate for TLS Jun 21, 2025
@CBenoit CBenoit disabled auto-merge June 21, 2025 15:53
@CBenoit CBenoit enabled auto-merge (squash) June 21, 2025 15:53
Copy link
Contributor

@pacmancoder pacmancoder left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! 🚀

@CBenoit CBenoit merged commit aca08f0 into master Jun 23, 2025
39 checks passed
@CBenoit CBenoit deleted the DGW-286 branch June 23, 2025 12:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants