浏览代码

Add serverAuth EKU to client certs for Service Mesh mTLS setups

Robert Panzer 5 年之前
父节点
当前提交
574ea52743
共有 1 个文件被更改,包括 1 次插入1 次删除
  1. 1 1
      cert.go

+ 1 - 1
cert.go

@@ -80,7 +80,7 @@ func (m *mkcert) makeCert(hosts []string) {
 	}
 
 	if m.client {
-		tpl.ExtKeyUsage = []x509.ExtKeyUsage{x509.ExtKeyUsageClientAuth}
+		tpl.ExtKeyUsage = []x509.ExtKeyUsage{x509.ExtKeyUsageClientAuth, x509.ExtKeyUsageServerAuth}
 	} else if len(tpl.IPAddresses) > 0 || len(tpl.DNSNames) > 0 {
 		tpl.ExtKeyUsage = []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth}
 	}