diff --git a/docs/https-app-gate-followup-20261006.md b/docs/https-app-gate-followup-20261006.md index 862aa3de..a37a36e9 100644 --- a/docs/https-app-gate-followup-20261006.md +++ b/docs/https-app-gate-followup-20261006.md @@ -92,3 +92,20 @@ explicitly. Build-time disk/memory pressure was also measured; the owned build was lowered in CPU/I/O priority without changing services. Neither observation proves the cause of every timeout. Normal certificate trust, the exact reported hostname/app, physical companion and restart/update persistence remain open. + +### Certificate identity validation (without bypass) + +Using each node's existing public trust material explicitly, dev's LAN IP +validates at443(HTTP200) and8083(HTTP401 without authentication). Yaya has no node +CA files: its legacy self-signed leaf contains only generic local DNS names and +127.0.0.1. Even when that leaf is explicitly trusted, its LAN IP fails certificate +identity validation (curl60); a DNS name actually listed on that certificate +validates and correctly returns401 at the app port. No certificate was replaced. + +This is an additional confirmed limitation, not proof of the reported exact +iframe gate cause. `scripts/setup-node-ca.sh` provides the intended node CA flow, +but review found its live key/cert install and nginx-listener edits need safe +staging/rollback before using it as repair. Preserve existing CA identities and +custom certificates; do not blindly regenerate trust. A client must explicitly +trust the node's public CA for normal browser validation. Keep normal-trust +acceptance open pending a tested provisioning repair and the operator's access URL. diff --git a/docs/post-1.9.0-work-backlog.md b/docs/post-1.9.0-work-backlog.md index 7de9c842..76e08e43 100644 --- a/docs/post-1.9.0-work-backlog.md +++ b/docs/post-1.9.0-work-backlog.md @@ -387,3 +387,17 @@ iframe loading, while unauthenticated requests still return401. Source fixes cover startup migration, hostname regeneration, first boot and explicit rotation; tests pass. Exact operator hostname/app, trusted TLS and companion acceptance remain open. See `docs/https-app-gate-followup-20261006.md`. + +## 18. Firewall and tunnel UI/settings — latest addition, last in sequence + +- Operator requested this at the end of the remaining tasks on6October, after + the previously deferred MeshCore work. Preserve the existing task order. +- Obtain and read the other agent's specific firewall/tunnel UI/settings handover + before fixing scope or implementing controls. It has not been located in the + local worktree documentation or temporary handoff files. Earlier NPM/public + management security handovers are received; they are not this new UI handover. +- Keep this item open as awaiting handover. Do not invent proposed settings or + mark receipt, implementation, deployment or acceptance complete. +- Once scoped, require tests of authorization, network-policy boundaries, + persistence, rollback and actual-node UI behavior without compromising + management access, existing tunnels or the public-management source guard.