Skip to content

Root CA fallback to system bundle (bsc#1262720) - #84

Merged
cbosdo merged 3 commits into
uyuni-project:masterfrom
cbosdo:ca-fallback
Jun 3, 2026
Merged

cbosdo merged 3 commits into
uyuni-project:masterfrom
cbosdo:ca-fallback

Conversation

@cbosdo

@cbosdo cbosdo commented Jun 3, 2026

Copy link
Copy Markdown
Contributor

Creating a new certificate bundle completely ignores the system trusted CAs. This may be fine if there is no error when getting the peripheral systems IDs… This PR uses the system CAs and adds the ones we got to it. This doesn't alter the system bundle, but at least we have a chance to be able to continue if anything wrong happened (like null Root CA throwing an exception).

To also help debugging what happens on the client side, I added a HUB_TRACE_CLIENT env variable.

cbosdo added 3 commits May 27, 2026 18:17
If an error happens when listing the peripheral IDs, we won't get the
root CAs. With some luck they can be the same than the hub root CA that
is mounted in the container. In this case, using the system bundle and
adding the fetch root CAs would prevent obscure errors.
@cbosdo
cbosdo requested a review from nadvornik June 3, 2026 08:12

@nadvornik nadvornik left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@cbosdo
cbosdo merged commit 6527e8f into uyuni-project:master Jun 3, 2026
2 checks passed
@cbosdo
cbosdo deleted the ca-fallback branch June 3, 2026 13:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants