iya-sts
    Preparing search index...

    The transport policy of every outbound request to an address somebody else answers: whether it may be plain http, and whether the certificate of whoever answers is verified.

    Each family has three settings (allow http, skip verification, a CA file); product mode refuses plain http and ignores a switch that skips verification.

    Index
    CA_FILE_CODE: "STS-CORE-0104" = CA_FILE_CODE

    The error code of a CA file setting that names an unusable file: STS-CORE-0104.

    • Reads the certificates in a PEM file.

      Parameters

      • file: string

        the file's path

      Returns string | string[]

      the PEM certificates, or a sentence saying why there are none

    • Holds a verified peer chain to the path rules without checking the host name, for a request that deliberately names no host (SPIRE's kubelet).

      Parameters

      • host: string

        the host dialled, for the message

      • cert: any

        the peer certificate node verified

      Returns Error

      an Error when the chain breaks the rules, otherwise undefined

    • The host check every verified outbound request makes: the host against the certificate's names, then the verified chain against the path rules.

      Parameters

      • host: string

        the host dialled

      • cert: any

        the peer certificate node verified

      Returns Error

      an Error when either check fails, otherwise undefined

    • Describes a family's three settings as they are in force here, which in product is not what is stored.

      Parameters

      • family: OutboundFamily

        the family's settings

      Returns {
          allowHttp: boolean;
          caFile: string;
          skipTlsVerification: boolean;
          skipTlsVerificationSet: boolean;
      }

      { allowHttp, skipTlsVerification, skipTlsVerificationSet, caFile }

    • Checks a host against a certificate's names as RFC 9525 reads them: subjectAltName DNS-IDs and IP-IDs only, a wildcard only as a whole left-most label, never the common name.

      Parameters

      • host: string

        the host name or IP address dialled

      • cert: any

        the peer certificate, as node describes it

      Returns string

      '' when the certificate names the host, otherwise a sentence saying why not

    • Decides whether an http:// URL may be dialled for a family.

      Development allows any host while the family's setting is on; product refuses, except a loopback host for a family that allows one.

      Parameters

      • family: OutboundFamily

        the family's settings and error codes

      • hostname: unknown

        the URL's host

      Returns HttpVerdict

      { ok, why, errorCode }

    • Makes the RFC 9525 host check and the path rules node's default checkServerIdentity for every TLS client in this process. Idempotent.

      Returns void

    • Tells whether a host name is a loopback address: localhost, 127.0.0.0/8 or ::1.

      Parameters

      • hostname: unknown

        the host name, IPv6 brackets allowed

      Returns boolean

      true for a loopback address

    • Tells whether certificate verification is to be skipped: only when the setting is on and the mode allows it.

      In product a setting that is on is ignored, and said once per process with the code given.

      Parameters

      • settingKey: string

        the setting that asks to skip verification

      • ignoredCode: string

        the error code logged when product ignores it

      • what: string

        what is being sent, for the log line

      Returns boolean

      true when verification is skipped

    • Builds the TLS options for one request of a family: verification skipped, node's store, or node's store plus the family's CA file.

      Never throws; an unusable CA file is ok: false with a sentence.

      Parameters

      • family: OutboundFamily

        the family's settings and error codes

      • origin: string

        where the request goes, for the log line

      Returns TlsVerdict

      { ok, why, errorCode, rejectUnauthorized, skipped }, with ca and checkServerIdentity where verifying

    • Builds the options for a verified outbound connection that is not one of the families: verification on, the RFC 9525 host check, and any CA given beside node's store.

      Parameters

      • Optionalca: string | string[]

        extra CA certificates, as PEM text or a list

      • Optionaloptions: { systemRoots?: boolean }

        systemRoots: false trusts ca ALONE, without node's store (#94: a connection whose operator named its own chain); ignored when no ca is given, which would trust nothing

      Returns {
          ca?: string[];
          checkServerIdentity: (host: string, cert: any) => Error;
          rejectUnauthorized: true;
      }

      the TLS options