Skip to content

Add ca_bundle profile option to trust a private CA - #149

Open
eaxi wants to merge 1 commit into
lance0:masterfrom
eaxi:pr-a-cabundle
Open

eaxi wants to merge 1 commit into
lance0:masterfrom
eaxi:pr-a-cabundle

Conversation

@eaxi

@eaxi eaxi commented Oct 6, 2026

Copy link
Copy Markdown

Problem

nbox builds reqwest with the bundled Mozilla root store, which contains no private CAs. A NetBox served by an internal/enterprise CA therefore fails with invalid peer certificate: UnknownIssuer. The only escape hatch was verify_tls = false — an all-or-nothing switch that disables verification altogether and would expose the NetBox token to anyone able to intercept the connection.

Change

[profiles.<name>].ca_bundle = "/path/ca.pem" — a PEM file (may hold the whole chain) whose certificates are added to the default roots. The certificate still has to verify; nothing is replaced or switched off.

Fail-fast: a bundle that cannot be read, or that parses to zero certificates, is an error at client construction — not a silently unverified connection at the first request, far from the typo that caused it.

Docs updated where verify_tls = false was previously the only advice (README, CONFIG, TROUBLESHOOTING, examples/config.toml): prefer trust anchors, keep verify_tls = false as the lab-only last resort.

Checks

cargo fmt --all -- --check clean; cargo clippy --all-targets --all-features -D warnings clean; cargo build clean; cargo test --all-features 1384 passed / 0 failed (25 binaries; the +3 over master are the new ca_bundle unit tests: bundle added to roots, unreadable bundle errors, empty bundle errors). Run on Rust 1.98, what upstream CI's dtolnay/rust-toolchain@stable currently resolves to.

nbox builds reqwest with the bundled Mozilla root store, which contains no
private CAs, so a NetBox served by an internal/enterprise CA fails with
`invalid peer certificate: UnknownIssuer`. The only existing escape hatch was
`verify_tls = false`.

That hatch is too blunt: disabling verification accepts *any* certificate,
which would expose the NetBox token to anyone able to intercept the
connection. Add `[profiles.<name>].ca_bundle`, a PEM file whose certificates
are *added* to the default roots — the certificate still has to verify.

A bundle that cannot be read, or that parses to zero certificates, is an
error at client construction. The alternative is building a client with no
extra roots and surfacing a confusing `UnknownIssuer` at the first request,
far from the typo that caused it.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant