Add ssl fix for certificates with different hostname than the IP and doc improvement

This commit is contained in:
Carlos Monastyrski
2025-08-28 14:38:49 -03:00
parent 5eee99e9ac
commit 4b42f7b1b5
4 changed files with 18 additions and 7 deletions
@@ -107,13 +107,13 @@ const normalizeAdcsUrl = (url: string): string => {
const createHttpsAgent = (sslRejectUnauthorized: boolean, sslCertificate?: string): https.Agent => {
const agentOptions: https.AgentOptions = {
rejectUnauthorized: sslRejectUnauthorized,
keepAlive: true // axios-ntlm needs keepAlive for NTLM handshake
keepAlive: true, // axios-ntlm needs keepAlive for NTLM handshake
ca: sslCertificate ? [sslCertificate.trim()] : undefined,
// Disable hostname verification as Microsoft servers by default use local IPs for certificates
// which may not match the hostname used to connect
checkServerIdentity: () => undefined
};
if (sslCertificate && sslCertificate.trim()) {
agentOptions.ca = [sslCertificate.trim()];
}
return new https.Agent(agentOptions);
};