You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Tracking two issues we observed with CSRs from ztunnel:
Sidecar CSRs have a Subject of O= (organization blank), ztunnels CSRs do not have a Subject
When using the tls-ring feature, the CSR does not set the SAN extension as critical
is causing an issue with Istio RA's verification, discussion here
when combined with 1., causes issue with specific issuers (e.g. AWS PCA returns error MalformedCSRException: CSR must mark the SAN extension critical when it has an empty subject.)
The text was updated successfully, but these errors were encountered:
Tracking two issues we observed with CSRs from ztunnel:
Subject
ofO=
(organization blank), ztunnels CSRs do not have a Subjecttls-ring
feature, the CSR does not set the SAN extension as criticalMalformedCSRException: CSR must mark the SAN extension critical when it has an empty subject.
)The text was updated successfully, but these errors were encountered: