mirror of
https://github.com/openziti/ziti.git
synced 2026-09-10 16:55:41 +00:00
3e6f0f2a76
- verifies the control-channel peer leaf against the controller's full trusted-CA pool (identity.CA()) instead of only self-signed roots, honoring intermediate trust anchors and multi-root bundles - drops the client-auth extended-key-usage requirement so an externally managed PKI with arbitrary or absent EKUs is not rejected