Skip to content

Conversation

@ameba23
Copy link
Collaborator

@ameba23 ameba23 commented Nov 7, 2025

This adds a command to get the TLS certificate from a ProxyServer instance if its attestation can be validated.

If successful it writes the certificate chain to standard output as PEM.

This is designed to be used the same way the attested-get command from cvm-reverse-proxy is used - it allows us the get the cert chain so that it can be used in subsequent non-attested connections to another service using this certificate.

@ameba23 ameba23 merged commit 5af89e4 into main Nov 7, 2025
2 checks passed
@ameba23 ameba23 deleted the peg/get-tls-cert branch November 7, 2025 09:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant