Files
tech-log-backend/infra/httpclient/tls/README.md
T

722 B

TLS fixtures

Certificates are generated in process by TlsFixture, not checked in. A committed private key is a private key that leaks, and design §21.2 forbids key material in the repository.

TlsFixture produces, from a throwaway CA created per test run:

Fixture Purpose
TlsFixture.trusted() a server certificate valid for the loopback host
TlsFixture.hostnameMismatch() a certificate whose SAN does not match the connection host
TlsFixture.expired() an already-expired certificate
clientHandshake(true) client key material for the mTLS lane

All three failure cases must classify as permanent (design §21.3) — never retried, never downgraded to plaintext.