Track firewall tunnel settings handover and certificate identity gap

This commit is contained in:
archipelago
2026-10-06 16:57:03 -04:00
parent 96dfed1ec5
commit 876a069d06
2 changed files with 31 additions and 0 deletions
+17
View File
@@ -92,3 +92,20 @@ explicitly. Build-time disk/memory pressure was also measured; the owned build
was lowered in CPU/I/O priority without changing services. Neither observation
proves the cause of every timeout. Normal certificate trust, the exact reported
hostname/app, physical companion and restart/update persistence remain open.
### Certificate identity validation (without bypass)
Using each node's existing public trust material explicitly, dev's LAN IP
validates at443(HTTP200) and8083(HTTP401 without authentication). Yaya has no node
CA files: its legacy self-signed leaf contains only generic local DNS names and
127.0.0.1. Even when that leaf is explicitly trusted, its LAN IP fails certificate
identity validation (curl60); a DNS name actually listed on that certificate
validates and correctly returns401 at the app port. No certificate was replaced.
This is an additional confirmed limitation, not proof of the reported exact
iframe gate cause. `scripts/setup-node-ca.sh` provides the intended node CA flow,
but review found its live key/cert install and nginx-listener edits need safe
staging/rollback before using it as repair. Preserve existing CA identities and
custom certificates; do not blindly regenerate trust. A client must explicitly
trust the node's public CA for normal browser validation. Keep normal-trust
acceptance open pending a tested provisioning repair and the operator's access URL.
+14
View File
@@ -387,3 +387,17 @@ iframe loading, while unauthenticated requests still return401. Source fixes
cover startup migration, hostname regeneration, first boot and explicit rotation;
tests pass. Exact operator hostname/app, trusted TLS and companion acceptance
remain open. See `docs/https-app-gate-followup-20261006.md`.
## 18. Firewall and tunnel UI/settings — latest addition, last in sequence
- Operator requested this at the end of the remaining tasks on6October, after
the previously deferred MeshCore work. Preserve the existing task order.
- Obtain and read the other agent's specific firewall/tunnel UI/settings handover
before fixing scope or implementing controls. It has not been located in the
local worktree documentation or temporary handoff files. Earlier NPM/public
management security handovers are received; they are not this new UI handover.
- Keep this item open as awaiting handover. Do not invent proposed settings or
mark receipt, implementation, deployment or acceptance complete.
- Once scoped, require tests of authorization, network-policy boundaries,
persistence, rollback and actual-node UI behavior without compromising
management access, existing tunnels or the public-management source guard.