Skip to content

W-23941710: Document CloudHub 2.0 SNI requirement for mTLS - #490

Open
kevintroller wants to merge 1 commit into
latestfrom
W-23941710-ch2-edge-runtime-kt
Open

W-23941710: Document CloudHub 2.0 SNI requirement for mTLS#490
kevintroller wants to merge 1 commit into
latestfrom
W-23941710-ch2-edge-runtime-kt

Conversation

@kevintroller

Copy link
Copy Markdown
Contributor

Summary

Documents the CloudHub 2.0 ingress behavior after W-23372389: when a private-space TLS context includes a truststore (partial client authentication), the load balancer rejects TLS connections that don't include SNI.

  • Adds an important note to the Truststore section of ps-config-domains.adoc.
  • Explains that clients must send SNI matching the custom domain, that connecting to the load balancer IP typically omits SNI, and that the handshake fails with an unrecognized name alert.

Test plan

  • Preview the CloudHub 2.0 page Configuring Domains and Certificates (TLS Context) for a Private Space and confirm the note renders under Truststore.
  • Confirm the note is accurate with engineering: rejection applies when mTLS/partial client authentication is enabled (not for all TLS connections).

@kevintroller
kevintroller requested a review from a team as a code owner September 1, 2026 14:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant