x509: certificate signed by unknown authority in Teleport Proxy Service
29K reputation · 10 Jan 2021, 04:15 UTC
When deploying Teleport in a production environment, the Proxy Service must establish a trusted TLS connection to the Auth Service. In local tests the connection succeeds when the Proxy is started with --insecure or when the internal CA is manually added to the host trust store. In production, without --insecure and relying only on the system CA bundle, the Proxy logs the error x509: certificate signed by unknown authority. The unresolved decision is how to configure trust for the internal CA while avoiding insecure TLS bypasses and without altering the global system trust store.
Consider the trade‑offs between pointing the Proxy to the internal CA via --auth.ca-file versus re‑issuing the Auth Service certificate from a publicly trusted CA, taking into account certificate rotation, proxy restart requirements, and compliance with internal security policies.
Should the Proxy be configured with --auth.ca-file pointing to the internal CA bundle, or should the Auth Service be re‑issued a certificate from a public CA? What operational impact does each option have on certificate renewal, proxy restarts, and cluster‑wide trust management?