Repository navigation
docs: administration: transport-security: document tls.verify_client_cert and tls.verify interaction - #2730
Conversation
…cert and tls.verify interaction
- Extend the tls.verify_client_cert row with the tls.verify interaction:
from v5.1.3, enabling it forces certificate validation even when
tls.verify is off, and Fluent Bit warns when both are combined.
- Add a v5.1 upgrade note covering the behavior change. Listeners that
set tls.verify off with tls.verify_client_cert on previously accepted
any client, and now reject clients without a CA-signed certificate.
- Fix a pre-existing THe typo in the v1.1 Tag section.
Signed-off-by: Eric D. Schabell <eric@schabell.org>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. 📝 WalkthroughWalkthroughThe transport security reference and upgrade notes document how ChangesTLS documentation
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Other Merge Risk: ⚪ Minimal · up to The documentation accurately reflects the verified TLS behavior, with no established merge-blocking risk. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Set as draft waiting on 5.1.3 release. |
|
@patrick-stephens ready for review, 5.1.3 dropped. |
from v5.1.3, enabling it forces certificate validation even when
tls.verify is off, and Fluent Bit warns when both are combined.
set tls.verify off with tls.verify_client_cert on previously accepted
any client, and now reject clients without a CA-signed certificate.
Summary by CodeRabbit
tls.verify_client_certrequires client certificates to pass validation even whentls.verifyis off. Fluent Bit warns when both settings are used and rejects clients without a certificate signed by the configured CA.tls.verify_client_certto accept clients without certificates.