Static ReadonlyCA_The error code of a CA file setting that names an unusable file:
STS-CORE-0104.
StaticcaReads the certificates in a PEM file.
the file's path
the PEM certificates, or a sentence saying why there are none
StaticcheckHolds a verified peer chain to the path rules without checking the host name, for a request that deliberately names no host (SPIRE's kubelet).
the host dialled, for the message
the peer certificate node verified
an Error when the chain breaks the rules, otherwise undefined
StaticcheckThe host check every verified outbound request makes: the host against the certificate's names, then the verified chain against the path rules.
the host dialled
the peer certificate node verified
an Error when either check fails, otherwise undefined
StaticdescribeDescribes a family's three settings as they are in force here, which in product is not what is stored.
the family's settings
{ allowHttp, skipTlsVerification, skipTlsVerificationSet, caFile }
StatichostChecks a host against a certificate's names as RFC 9525 reads them: subjectAltName DNS-IDs and IP-IDs only, a wildcard only as a whole left-most label, never the common name.
the host name or IP address dialled
the peer certificate, as node describes it
'' when the certificate names the host, otherwise a sentence saying why not
StatichttpDecides whether an http:// URL may be dialled for a family.
Development allows any host while the family's setting is on; product refuses, except a loopback host for a family that allows one.
the family's settings and error codes
the URL's host
{ ok, why, errorCode }
StaticinstallMakes the RFC 9525 host check and the path rules node's default
checkServerIdentity for every TLS client in this process. Idempotent.
StaticisTells whether a host name is a loopback address: localhost, 127.0.0.0/8 or ::1.
the host name, IPv6 brackets allowed
true for a loopback address
StaticskipsTells whether certificate verification is to be skipped: only when the setting is on and the mode allows it.
In product a setting that is on is ignored, and said once per process with the code given.
the setting that asks to skip verification
the error code logged when product ignores it
what is being sent, for the log line
true when verification is skipped
StatictlsBuilds the TLS options for one request of a family: verification skipped, node's store, or node's store plus the family's CA file.
Never throws; an unusable CA file is ok: false with a sentence.
the family's settings and error codes
where the request goes, for the log line
{ ok, why, errorCode, rejectUnauthorized, skipped }, with ca
and checkServerIdentity where verifying
StaticverifiedBuilds the options for a verified outbound connection that is not one of the families: verification on, the RFC 9525 host check, and any CA given beside node's store.
Optionalca: string | string[]
extra CA certificates, as PEM text or a list
Optionaloptions: { systemRoots?: boolean }
systemRoots: false trusts ca ALONE, without node's
store (#94: a connection whose operator named its own chain); ignored
when no ca is given, which would trust nothing
the TLS options
The transport policy of every outbound request to an address somebody else answers: whether it may be plain http, and whether the certificate of whoever answers is verified.
Each family has three settings (allow http, skip verification, a CA file); product mode refuses plain http and ignores a switch that skips verification.