mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-10-06 19:53:08 +00:00
Tests 18 and 19 failed inside TLS before a single frame was written: CRYPTO_ERROR (TLS alert 42): certificate chain validation failed: PKIX path building failed: unable to find valid certification path The reference broker generates a self-signed certificate — its startup JSON says so, `"tls":"generated_self_signed"` — and there is no CA anywhere in this picture, so chaining it to the JDK trust store could never have worked. The binding anticipates exactly this: a client MAY pin the endpoint certificate by SHA-256 instead of chaining, which is what `--pin-sha256` and `PinnedCertificateValidator` are for. The broker prints the fingerprint the pin needs, in the same JSON line the harness already waits on; the harness just never read it. So `start_quic_broker` now captures `server_cert_sha256_fingerprint` and fails loudly if it is absent, and the three `amy marmot stream send|watch` calls pass it. `wn` reaches the same place with `--insecure-local`; pinning is the better half of that trade, since the peer still has to sign the TLS transcript with the pinned certificate's private key. 25 passed, 0 failed, 0 skipped. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016kCuA6tc4JQzHPCDd39GHq