mirror of
https://github.com/openziti/ziti.git
synced 2026-09-11 13:29:03 +00:00
6b342c9515
- verifies the control-channel peer leaf against the controller's full trusted-CA pool (identity.CA()) instead of only self-signed roots, honoring intermediate trust anchors and multi-root bundles - drops the client-auth extended-key-usage requirement so an externally managed PKI with arbitrary or absent EKUs is not rejected