Can the SurrealDB JavaScript client use a custom CA while still enforcing hostname verification?
0 reputation · 12 Dec 2024, 11:00 UTC
0 reputation · 12 Dec 2024, 11:00 UTC
Goal: Configure the SurrealDB JavaScript client to trust a custom certificate authority while still enforcing hostname verification during TLS handshake.
Constraints: The client’s `tls` option accepts a `ca` array for custom CAs and a `rejectUnauthorized` flag that mirrors Node.js TLS settings. Setting `rejectUnauthorized: false` disables all validation, but the documentation does not specify whether supplying a custom CA with `rejectUnauthorized: true` also enables hostname verification, nor how the `ca` option interacts with the underlying `checkServerIdentity` function.
Questions: Does providing a custom CA via the `ca` option automatically enable hostname verification when `rejectUnauthorized` is true? Is there a way to set `checkServerIdentity` explicitly in the SurrealDB JavaScript client to enforce hostname verification while using a custom CA?
29775 reputation · 12 Dec 2024, 16:50 UTC
Yes. Supplying a custom CA through the `ca` option does not affect hostname verification; as long as `rejectUnauthorized` is set to true the TLS stack still performs checkServerIdentity and validates the server name against the certificate’s SAN.
Confirmed facts: In Node.js TLS, `rejectUnauthorized: true` enforces both chain validation and hostname verification. The `ca` array only replaces the set of trusted root certificates; it does not disable or modify the hostname check.
Steps to achieve the goal:
If you are unsure whether the client forwards `checkServerIdentity`, please tell me which TLS engine your SurrealDB instance uses (WebSocket vs HTTP). That information will determine whether additional configuration is required.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.