Ory Oathkeeper Upstream TLS Verification Default Behavior
26K reputation · 18 Jun 2023, 19:09 UTC
The goal is to configure Ory Oathkeeper so that any request forwarded to an upstream API is only allowed when the TLS certificate presented by the upstream matches the hostname in the configured upstream URL.
However, the documentation does not explicitly state the default behavior of the skip_tls_verify flag when it is omitted, nor does it clarify whether Ory Oathkeeper performs DNS‑based validation (checking that the resolved IP address corresponds to a name in the certificate’s SAN) by default. This leaves an unresolved decision about what constitutes a secure default configuration for upstream TLS verification.
What is the effective default of skip_tls_verify when the flag is not set? Should Ory Oathkeeper enforce hostname‑based TLS verification by default, requiring explicit opt‑out to disable it? Should DNS‑based validation be performed automatically, or must it be enabled via a separate option?