Skip to content

Pinniped TLS handshake with ingress #1483

Answered by cfryanr
HamzaZo asked this question in Q&A
Discussion options

You must be logged in to vote

Hi @HamzaZo, are you using a DNS hostname for the Supervisor, or are you using an IP address to access the Supervisor?

If you are trying to use a DNS name, when your Ingress makes the HTTPS request to its backend, does it preserve the hostname of the original request or set the Host header to pass-through the hostname of the original request? The Supervisor uses SNI (hostname on the request or Host header on the request) to find the TLS certificate configured on your FederationDomain. To help debug, you can turn on trace logging for the Supervisor and then watch for this log message during a request: https://github.com/vmware-tanzu/pinniped/blob/v0.23.0/internal/supervisor/server/server.g…

Replies: 3 comments 7 replies

Comment options

You must be logged in to vote
2 replies
@HamzaZo
Comment options

@cfryanr
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
5 replies
@HamzaZo
Comment options

@HamzaZo
Comment options

@cfryanr
Comment options

@cfryanr
Comment options

@HamzaZo
Comment options

Answer selected by HamzaZo
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants