public static interface CfnVirtualNode.TlsValidationContextProperty
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import software.amazon.awscdk.services.appmesh.*; TlsValidationContextProperty tlsValidationContextProperty = TlsValidationContextProperty.builder() .trust(TlsValidationContextTrustProperty.builder() .acm(TlsValidationContextAcmTrustProperty.builder() .certificateAuthorityArns(List.of("certificateAuthorityArns")) .build()) .file(TlsValidationContextFileTrustProperty.builder() .certificateChain("certificateChain") .build()) .sds(TlsValidationContextSdsTrustProperty.builder() .secretName("secretName") .build()) .build()) // the properties below are optional .subjectAlternativeNames(SubjectAlternativeNamesProperty.builder() .match(SubjectAlternativeNameMatchersProperty.builder() .exact(List.of("exact")) .build()) .build()) .build();
Modifier and Type | Interface and Description |
---|---|
static class |
CfnVirtualNode.TlsValidationContextProperty.Builder
A builder for
CfnVirtualNode.TlsValidationContextProperty |
static class |
CfnVirtualNode.TlsValidationContextProperty.Jsii$Proxy
An implementation for
CfnVirtualNode.TlsValidationContextProperty |
Modifier and Type | Method and Description |
---|---|
static CfnVirtualNode.TlsValidationContextProperty.Builder |
builder() |
default java.lang.Object |
getSubjectAlternativeNames()
A reference to an object that represents the SANs for a Transport Layer Security (TLS) validation context.
|
java.lang.Object |
getTrust()
A reference to where to retrieve the trust chain when validating a peer’s Transport Layer Security (TLS) certificate.
|
java.lang.Object getTrust()
default java.lang.Object getSubjectAlternativeNames()
If you don't specify SANs on the terminating mesh endpoint, the Envoy proxy for that node doesn't verify the SAN on a peer client certificate. If you don't specify SANs on the originating mesh endpoint, the SAN on the certificate provided by the terminating endpoint must match the mesh endpoint service discovery configuration. Since SPIRE vended certificates have a SPIFFE ID as a name, you must set the SAN since the name doesn't match the service discovery name.
static CfnVirtualNode.TlsValidationContextProperty.Builder builder()