Skip to content

Step-ca should be able to respond over plain HTTPΒ #246

@t0xicCode

Description

@t0xicCode

As per the discussion #193, step-ca should be able to expose an HTTP port instead of only an HTTPS (or in addition to an HTTPS).

There are situations where the use of HTTPS at the step-ca level is unnecessary or nearly impossible, such as when tls terminating load balancers as used.

If HTTPS is still to be enforced, step could require that either the connection be TLS or that the connection come from a trusted IP and that X-Forwarded-Proto be set to https.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions