coder / coder/coder-jetbrains-toolbox

REST API client does not fall back to the OS trusted keystore

Open
#91 0 comments 0 reactions 1 assignee Claimed by @fioan89 View on GitHub
upstream
Dominant language
Kotlin
Stars
23
Forks
7
Avg merge
3d 12h
Merged PRs (30d)
10

Description

While testing the proxy support in the plugin with mitmproxy we've noticed that the REST client does not fallback to the OS trusted certificates if it can't find anything in the JVM's default keystore.

Mitmproxy uses self-signed certificates, and it's usually simpler to add the certificate required to the operating system's certificate trust store rather than Toolbox JVM's default keystore. However, by default, JVM-based applications use only the JVM's default keystore, which means connecting to servers will fail due to not trusting the certificate presented.

Ideally, the plugin cascades in the following order:

- JVM's default keystore
- Coder configured CA (available in the Settings page under TLS section)
- OS trusted keystore

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.