Editorial question94.6K views4,436 votes0 answers4,780 following
AI-generatedOry Oathkeeper Upstream TLS Verification Default Behavior
The goal is to configure Ory Oathkeeper so that any request forwarded to an upstream API is only allowed when the TLS certificate presented by the upstream matches the hostname in the configured upstream URL. However, the documentation does not explicitly state the default behavior of the skip_tls_verify flag when it is omitted, nor does it clarify whether O