mirror of
https://github.com/XRPLF/rippled.git
synced 2026-10-11 06:08:02 +00:00
docs: State the use_tls endpoint invariant in positive terms
Reword the two use_tls comments in the enabled branch to state the invariant directly. A client certificate always implies use_tls=1, and use_tls=1 requires an https endpoint, enforced at startup. Keep the note that tls_ca_cert is not checked this way.
This commit is contained in:
@@ -337,10 +337,9 @@ makeTelemetrySetup(
|
||||
}
|
||||
|
||||
// Still inside the enabled branch. mTLS only takes effect when TLS is
|
||||
// on, so a client certificate set with use_tls=0 would be ignored and
|
||||
// any exporter that did run would connect in plaintext. Reject that
|
||||
// contradiction instead of failing open. tls_ca_cert is deliberately
|
||||
// not checked this way.
|
||||
// on, so a client certificate set with use_tls=0 would be ignored.
|
||||
// Reject that contradiction so a client certificate always implies
|
||||
// use_tls=1. tls_ca_cert is deliberately not checked this way.
|
||||
if (!setup.tlsClientCertPath.empty() && !setup.useTls)
|
||||
{
|
||||
Throw<std::runtime_error>(
|
||||
@@ -350,10 +349,9 @@ makeTelemetrySetup(
|
||||
|
||||
// Still inside the enabled branch, and checked before the files are
|
||||
// opened so a scheme problem is not hidden behind a path problem. The
|
||||
// exporter reads TLS off the endpoint scheme alone, so use_tls=1 on an
|
||||
// http endpoint would validate the certificate files and then still
|
||||
// export in the clear. An operator who asks for TLS gets TLS or a
|
||||
// startup error, never plaintext.
|
||||
// exporter selects TLS from the endpoint scheme, so use_tls=1 requires
|
||||
// an https endpoint, enforced here at startup. An operator who asks for
|
||||
// TLS gets it, or a startup error.
|
||||
if (setup.useTls)
|
||||
{
|
||||
requireHttpsEndpoint(setup.tracesEndpoint, key::tracesEndpoint);
|
||||
|
||||
Reference in New Issue
Block a user