mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-11 14:28:56 +00:00
Add ssl fix for certificates with different hostname than the IP and doc improvement
This commit is contained in:
@@ -107,13 +107,13 @@ const normalizeAdcsUrl = (url: string): string => {
|
||||
const createHttpsAgent = (sslRejectUnauthorized: boolean, sslCertificate?: string): https.Agent => {
|
||||
const agentOptions: https.AgentOptions = {
|
||||
rejectUnauthorized: sslRejectUnauthorized,
|
||||
keepAlive: true // axios-ntlm needs keepAlive for NTLM handshake
|
||||
keepAlive: true, // axios-ntlm needs keepAlive for NTLM handshake
|
||||
ca: sslCertificate ? [sslCertificate.trim()] : undefined,
|
||||
// Disable hostname verification as Microsoft servers by default use local IPs for certificates
|
||||
// which may not match the hostname used to connect
|
||||
checkServerIdentity: () => undefined
|
||||
};
|
||||
|
||||
if (sslCertificate && sslCertificate.trim()) {
|
||||
agentOptions.ca = [sslCertificate.trim()];
|
||||
}
|
||||
|
||||
return new https.Agent(agentOptions);
|
||||
};
|
||||
|
||||
|
||||
Reference in New Issue
Block a user