Track firewall tunnel settings handover and certificate identity gap
This commit is contained in:
@@ -92,3 +92,20 @@ explicitly. Build-time disk/memory pressure was also measured; the owned build
|
||||
was lowered in CPU/I/O priority without changing services. Neither observation
|
||||
proves the cause of every timeout. Normal certificate trust, the exact reported
|
||||
hostname/app, physical companion and restart/update persistence remain open.
|
||||
|
||||
### Certificate identity validation (without bypass)
|
||||
|
||||
Using each node's existing public trust material explicitly, dev's LAN IP
|
||||
validates at443(HTTP200) and8083(HTTP401 without authentication). Yaya has no node
|
||||
CA files: its legacy self-signed leaf contains only generic local DNS names and
|
||||
127.0.0.1. Even when that leaf is explicitly trusted, its LAN IP fails certificate
|
||||
identity validation (curl60); a DNS name actually listed on that certificate
|
||||
validates and correctly returns401 at the app port. No certificate was replaced.
|
||||
|
||||
This is an additional confirmed limitation, not proof of the reported exact
|
||||
iframe gate cause. `scripts/setup-node-ca.sh` provides the intended node CA flow,
|
||||
but review found its live key/cert install and nginx-listener edits need safe
|
||||
staging/rollback before using it as repair. Preserve existing CA identities and
|
||||
custom certificates; do not blindly regenerate trust. A client must explicitly
|
||||
trust the node's public CA for normal browser validation. Keep normal-trust
|
||||
acceptance open pending a tested provisioning repair and the operator's access URL.
|
||||
|
||||
@@ -387,3 +387,17 @@ iframe loading, while unauthenticated requests still return401. Source fixes
|
||||
cover startup migration, hostname regeneration, first boot and explicit rotation;
|
||||
tests pass. Exact operator hostname/app, trusted TLS and companion acceptance
|
||||
remain open. See `docs/https-app-gate-followup-20261006.md`.
|
||||
|
||||
## 18. Firewall and tunnel UI/settings — latest addition, last in sequence
|
||||
|
||||
- Operator requested this at the end of the remaining tasks on6October, after
|
||||
the previously deferred MeshCore work. Preserve the existing task order.
|
||||
- Obtain and read the other agent's specific firewall/tunnel UI/settings handover
|
||||
before fixing scope or implementing controls. It has not been located in the
|
||||
local worktree documentation or temporary handoff files. Earlier NPM/public
|
||||
management security handovers are received; they are not this new UI handover.
|
||||
- Keep this item open as awaiting handover. Do not invent proposed settings or
|
||||
mark receipt, implementation, deployment or acceptance complete.
|
||||
- Once scoped, require tests of authorization, network-policy boundaries,
|
||||
persistence, rollback and actual-node UI behavior without compromising
|
||||
management access, existing tunnels or the public-management source guard.
|
||||
|
||||
Reference in New Issue
Block a user