[#800] ACME e2e proof: IP-identifier issuance validated on sectestbed 5104
ci / audit (push) Failing after 54s

http-01 validation, issuance, and chain all verified against the fleet
root via the prod endpoint; 5104 shut back down after the test.
https://projects.knownelement.com/issues/800
This commit is contained in:
2026-09-05 10:16:30 -05:00
parent d923b5f34b
commit d2541647f2
+17
View File
@@ -42,3 +42,20 @@ Consequences / rules for ACME http-01 across the fleet:
E2E proof plan: boot sectestbed VM (5104), run lego there with an IP E2E proof plan: boot sectestbed VM (5104), run lego there with an IP
identifier (fresh VM, port 80 free), issue via the prod endpoint. identifier (fresh VM, port 80 free), issue via the prod endpoint.
## E2E PROOF (2026-09-05) — http-01 issuance VERIFIED
sectestbed VM 5104 (dev PBS, tailnet 100.127.238.29, port 80 free):
lego --server https://100.102.96.24:8443/acme/acme/directory \
--email agent@knel.net --accept-tos \
--domains 100.127.238.29 --http run
→ Served key authentication → The server validated our request
→ Server responded with a certificate
Issuer: CN=KNEL Fleet ACME Intermediate (ECDSA, under fleet RSA root)
SAN: IP:100.127.238.29
IP identifiers work. DNS identifiers work when the name resolves from
tsys-ca (rooted FQDN — add /etc/hosts entry on tsys-ca for test names).
Verify chain: openssl verify -CAfile root.crt -untrusted issuer.crt leaf.crt
VM shut back down after the test (lane rule).