|
Stage 5 dc0 Step 7: triage F-CV1 (CONFIRMED designate bind-plane mismatch) + F-CV3; sweep
Operator-authorized triage of the two plaintext-vs-TLS findings (read-only; not fixed, hard rule 1). Both apps have vault certs rendered + the certificates relation, so NOT the ovn CN-issuance class -- charm apache-TLS-frontend layer. F-CV1 CONFIRMED (two findings, not one): designate/0 apache https frontend binds only 10.12.8.198:8991 (metal-admin); haproxy's _admin backend dials 10.12.12.110:8991 (metal-internal) where no SSL vhost exists -> check-ssl hits plaintext -> DOWN. VR1 dual-metal-plane bind mismatch (D-141), structural (not Stage-7 collateral). F-CV3 (dashboard) is separate: :433 served by Ubuntu default-ssl.conf, charm https frontend not effective; root cause not nailed. Owned instrument caveat: earlier "no SSLEngine in sites-enabled" was a grep -r false negative (does not follow the symlinks); apache2ctl -S corrected it. Remediation = a focused, gated session. Sweep: docs/audit/queued-findings-20260806-phase03-coreverify.txt Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728 |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/audit/queued-findings-20260806-phase03-coreverify.txt 0 → 100644 |
|---|
| docs/audit/stage5-dc0-phase03-coreverify-20260806.txt |
|---|