Files
nixos-servers/services/kanidm/default.nix
Torjus Håkestad de36b9d016
Some checks failed
Run nix flake check / flake-check (push) Failing after 1s
kanidm: add hostname SAN to ACME certificate
Include both auth.home.2rjus.net (CNAME) and kanidm01.home.2rjus.net
(A record) as SANs in the TLS certificate. This fixes Prometheus
scraping which connects via the hostname, not the CNAME.

Fixes: x509: certificate is valid for auth.home.2rjus.net, not kanidm01.home.2rjus.net

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-02-08 03:29:54 +01:00

1.7 KiB