Solution

meowOwner

Confirmed this is intentional, we reject self signed certificates at registration specifically to prevent a misconfigured endpoint from silently swallowing deliveries. A tunnel with a real certificate is the supported path for internal testing.

5 replies

That check is intentional, we reject self signed certificates at registration time so a misconfigured endpoint cannot silently swallow deliveries. For internal testing, a tunnel with a real certificate is the supported path instead of the load balancer directly.

Upvote1

Switched our internal testing to a tunnel like suggested, works fine now.

Upvote2

To be clear this only applies to registration, an already-registered endpoint whose cert later expires will just start failing deliveries, worth monitoring separately.

Upvote2
meowOwner
✓ Solution

Confirmed this is intentional, we reject self signed certificates at registration specifically to prevent a misconfigured endpoint from silently swallowing deliveries. A tunnel with a real certificate is the supported path for internal testing.

Upvote6

Sign in to reply to this question.

Powered by Forumcat