Project

General

Profile

Actions

User story #9624

closed

Add an option to check server certificate when sending inventory

Added by Alexis Mousset over 7 years ago. Updated over 4 years ago.

Status:
Rejected
Priority:
N/A
Assignee:
-
Category:
System techniques
Target version:
UX impact:
Suggestion strength:
User visibility:
Effort required:
Name check:
Fix check:
Regression:

Description

Currently all HTTPS communication between node and server use something like curl -k and never check the certificates. That means we do not know if we are sending the inventory to the right server.

As a first step, we could add an option to remove that -k option, and require the certificate to be checked by curl, which would be a big improvement for users that gave their CA (or use a known CA).


Related issues 1 (0 open1 closed)

Is duplicate of Rudder - Architecture #15513: Make certificate verification in HTTP calls configurableReleasedNicolas CHARLESActions
Actions

Also available in: Atom PDF