You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/control
Brad Fitzpatrick e92eb6b17b net/tlsdial: fix TLS cert validation of HTTPS proxies
If you had HTTPS_PROXY=https://some-valid-cert.example.com running a
CONNECT proxy, we should've been able to do a TLS CONNECT request to
e.g. controlplane.tailscale.com:443 through that, and I'm pretty sure
it used to work, but refactorings and lack of integration tests made
it regress.

It probably regressed when we added the baked-in LetsEncrypt root cert
validation fallback code, which was testing against the wrong hostname
(the ultimate one, not the one which we were being asked to validate)

Fixes #16222

Change-Id: If014e395f830e2f87f056f588edacad5c15e91bc
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
6 months ago
..
controlbase all: add Node.HomeDERP int, phase out "127.3.3.40:$region" hack [capver 111] 11 months ago
controlclient net/tlsdial: fix TLS cert validation of HTTPS proxies 6 months ago
controlhttp net/tlsdial: fix TLS cert validation of HTTPS proxies 6 months ago
controlknobs control/controlknobs: make Knobs.AsDebugJSON automatic, not require maintenance 10 months ago