Question
Can this project provide a fix so that client_cert_path sends the full certificate chain (leaf + intermediate CA), not only the first PEM?
We use mTLS with certificates issued by an Intermediate CA (cert-manager / Kubernetes TLS secret):
tls.crt = leaf, then intermediate(s)
tls.key = leaf private key
ca.crt = Root CA only
The HTTP server trusts the Root only. For the handshake to succeed, the client needs to present the Intermediate as well.
What happens today
client_cert_path is loaded here:
https://github.com/fluent-plugins-nursery/fluent-plugin-out-http/blob/v1.3.5/lib/fluent/plugin/out_http.rb
opts[:cert] = OpenSSL::X509::Certificate.new(File.read(@client_cert_path)) if File.file?(@client_cert_path)
That keeps only the first certificate in the file. When we point client_cert_path at a multi-PEM chain, mTLS to a Root-only server fails (unknown ca / certificate verify failed).
Observed on fluent-plugin-out-http 1.3.5. This plugin uses Net::HTTP directly (endpoint_url, client_cert_path). It is not Faraday, so http_backend typhoeus does not apply.
Will you provide a fix for this? If work is already planned, can you point us to the issue or target release so we can follow it?
Thanks.
Question
Can this project provide a fix so that
client_cert_pathsends the full certificate chain (leaf + intermediate CA), not only the first PEM?We use mTLS with certificates issued by an Intermediate CA (cert-manager / Kubernetes TLS secret):
tls.crt= leaf, then intermediate(s)tls.key= leaf private keyca.crt= Root CA onlyThe HTTP server trusts the Root only. For the handshake to succeed, the client needs to present the Intermediate as well.
What happens today
client_cert_pathis loaded here:https://github.com/fluent-plugins-nursery/fluent-plugin-out-http/blob/v1.3.5/lib/fluent/plugin/out_http.rb
That keeps only the first certificate in the file. When we point client_cert_path at a multi-PEM chain, mTLS to a Root-only server fails (unknown ca / certificate verify failed).
Observed on fluent-plugin-out-http 1.3.5. This plugin uses Net::HTTP directly (endpoint_url, client_cert_path). It is not Faraday, so http_backend typhoeus does not apply.
Will you provide a fix for this? If work is already planned, can you point us to the issue or target release so we can follow it?
Thanks.