Skip to content

Check host against CN/SAN of TLS certificate during JWT key auto-refresh #1934

@letmaik

Description

@letmaik

Currently, while auto-refreshing JWT keys, the stored CA cert is used to validate the TLS connection. However, the CN/SAN of the leaf cert sent within the TLS session (the actual website cert) is not checked against the domain name used for connecting.

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions