Skip to content

TLS: add CRL-related information to TRANSPORT_FAILURE_REASON #43642

@guydc

Description

@guydc

Title: TLS: add CRL-related information to TRANSPORT_FAILURE_REASON

Description:
Currently, operators are responsible for providing and maintaining CRLs used by Envoy proxy. CRL verification checks may fail due to not-yet-ready/expired CRLs or missing CRLs (e.g. for a new CRLDP not previously known to operators).

Similar to previous enhancements that included certificate SANs when SAN validation fails, adding certificate CRLDP and CRL-related error information to the TRANSPORT_FAILURE_REASON can help operators quickly troubleshoot issues.

[optional Relevant Links:]

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/tlsenhancementFeature requests. Not bugs or questions.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions