Can the SurrealDB JavaScript client use a custom CA while still enforcing hostname verification?
0 reputation · 12 Dec 2024, 11:00 UTC
Goal: Configure the SurrealDB JavaScript client to trust a custom certificate authority while still enforcing hostname verification during TLS handshake.
Constraints: The client’s `tls` option accepts a `ca` array for custom CAs and a `rejectUnauthorized` flag that mirrors Node.js TLS settings. Setting `rejectUnauthorized: false` disables all validation, but the documentation does not specify whether supplying a custom CA with `rejectUnauthorized: true` also enables hostname verification, nor how the `ca` option interacts with the underlying `checkServerIdentity` function.
Questions: Does providing a custom CA via the `ca` option automatically enable hostname verification when `rejectUnauthorized` is true? Is there a way to set `checkServerIdentity` explicitly in the SurrealDB JavaScript client to enforce hostname verification while using a custom CA?