Skip to content

3.0.0 Release Notes

Choose a tag to compare

@rdgallagher rdgallagher released this 08 Aug 18:20
· 239 commits to main since this release

SSL Validation

HTTPS targets now validate SSL certificates by default, instead of using OpenSSL::SSL::VERIFY_NONE.

In case you were relying on this behavior, this feature includes setting a flag on the target command which skips certificate validation for https Urls. If this flag is not set on the target, a Url with a bad certificate cannot be set as the target due to an SSL error. If the skip-ssl-validation flag is set, OpenSSL::SSL::VERIFY_NONE is used as the verify mode.

This setting is remembered per target - even when re-targetting the same URL. To clear it out, you can edit ~/.uaac.yml.

Note: Setting a target without specifying the scheme (eg. uaac target example.com), will not fallback to HTTP now. It will attempt HTTPS and stop at that if it fails.