Commit 9e6ecf8
Document mTLS revocation checking when the client certificate's issuer is unavailable (#659)
* Document how mTLS revocation checking behaves when the client certificate's issuer is unavailable
Harper now resolves the issuer from its configured certificate authorities when the
connection does not carry it (resumed TLS sessions, Node.js 26.8.0/26.8.1), and otherwise
applies failureMode instead of silently skipping the check. Companion to HarperFast/harper#2380.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* Note that proxy-forwarded client chains need the issuing CA configured on Harper too
* Place the version badge on its own line and split the failure-mode sentences
---------
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>1 parent 45a9dcc commit 9e6ecf8
1 file changed
Lines changed: 17 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
220 | 220 | | |
221 | 221 | | |
222 | 222 | | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
223 | 231 | | |
224 | 232 | | |
225 | 233 | | |
| |||
327 | 335 | | |
328 | 336 | | |
329 | 337 | | |
| 338 | + | |
| 339 | + | |
| 340 | + | |
| 341 | + | |
| 342 | + | |
| 343 | + | |
| 344 | + | |
| 345 | + | |
| 346 | + | |
330 | 347 | | |
331 | 348 | | |
332 | 349 | | |
| |||
0 commit comments