Skip to content
Discussion options

You must be logged in to vote

The option you see in the Join Cluster dialog is used only for the joining process. Here the joining node will check for the TLS certificate validity and if your zone is DNSSEC signed then it will check and use DANE. For DANE to work, the domain has to be publicly resolvable and signed with DNSSEC such that the TLSA record can be validated as per the standard process. Once the node joins the cluster, it will always use DANE-EE when when the cluster zone is a private zone that does not resolve over Internet.

Is it true that the Validate Certificate With PKI and DANE (Recommended) option only needs one of DANE-EE or PKI verification to be successful? And that it accepts empty TLSA records?

Replies: 2 comments 3 replies

Comment options

You must be logged in to vote
1 reply
@ShreyasZare
Comment options

Comment options

You must be logged in to vote
2 replies
@stratself
Comment options

@ShreyasZare
Comment options

Answer selected by stratself
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants