Skip to content

Commit f5c9a1b

Browse files
committed
Remove invalid TLS setting
OTP 26 no longer ignores `fail_if_no_peer_cert` for a `client` setting. Instead, distributed Erlang fails without informative error messages. See the following issues: * erlang/otp#7497 * rabbitmq/rabbitmq-website#1687 `customize_hostname_check` is client only
1 parent 90408d5 commit f5c9a1b

File tree

1 file changed

+2
-6
lines changed

1 file changed

+2
-6
lines changed

docs/examples/mtls-inter-node/inter_node_tls.config

Lines changed: 2 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -5,20 +5,16 @@
55
{keyfile, "/etc/rabbitmq/certs/tls.key"},
66
{secure_renegotiate, true},
77
{fail_if_no_peer_cert, true},
8-
{verify, verify_peer},
9-
{customize_hostname_check, [
10-
{match_fun, public_key:pkix_verify_hostname_match_fun(https)}
11-
]}
8+
{verify, verify_peer}
129
]},
1310
{client, [
1411
{cacertfile, "/etc/rabbitmq/certs/ca.crt"},
1512
{certfile, "/etc/rabbitmq/certs/tls.crt"},
1613
{keyfile, "/etc/rabbitmq/certs/tls.key"},
1714
{secure_renegotiate, true},
18-
{fail_if_no_peer_cert, true},
1915
{verify, verify_peer},
2016
{customize_hostname_check, [
2117
{match_fun, public_key:pkix_verify_hostname_match_fun(https)}
2218
]}
2319
]}
24-
].
20+
].

0 commit comments

Comments
 (0)