Interface CfnVirtualNodePropsMixin.TlsValidationContextProperty
- All Superinterfaces:
software.amazon.jsii.JsiiSerializable
- All Known Implementing Classes:
CfnVirtualNodePropsMixin.TlsValidationContextProperty.Jsii$Proxy
- Enclosing class:
CfnVirtualNodePropsMixin
@Stability(Stable)
public static interface CfnVirtualNodePropsMixin.TlsValidationContextProperty
extends software.amazon.jsii.JsiiSerializable
An object that represents how the proxy will validate its peer during Transport Layer Security (TLS) negotiation.
Example:
// The code below shows an example of how to instantiate this type.
// The values are placeholders you should change.
import software.amazon.awscdk.cfnpropertymixins.services.appmesh.*;
TlsValidationContextProperty tlsValidationContextProperty = TlsValidationContextProperty.builder()
.subjectAlternativeNames(SubjectAlternativeNamesProperty.builder()
.match(SubjectAlternativeNameMatchersProperty.builder()
.exact(List.of("exact"))
.build())
.build())
.trust(TlsValidationContextTrustProperty.builder()
.acm(TlsValidationContextAcmTrustProperty.builder()
.certificateAuthorityArns(List.of("certificateAuthorityArns"))
.build())
.file(TlsValidationContextFileTrustProperty.builder()
.certificateChain("certificateChain")
.build())
.sds(TlsValidationContextSdsTrustProperty.builder()
.secretName("secretName")
.build())
.build())
.build();
- See Also:
-
Nested Class Summary
Nested ClassesModifier and TypeInterfaceDescriptionstatic final classA builder forCfnVirtualNodePropsMixin.TlsValidationContextPropertystatic final classAn implementation forCfnVirtualNodePropsMixin.TlsValidationContextProperty -
Method Summary
Modifier and TypeMethodDescriptionbuilder()default ObjectA reference to an object that represents the SANs for a Transport Layer Security (TLS) validation context.default ObjectgetTrust()A reference to where to retrieve the trust chain when validating a peer’s Transport Layer Security (TLS) certificate.Methods inherited from interface software.amazon.jsii.JsiiSerializable
$jsii$toJson
-
Method Details
-
getSubjectAlternativeNames
A reference to an object that represents the SANs for a Transport Layer Security (TLS) validation context.If you don't specify SANs on the terminating mesh endpoint, the Envoy proxy for that node doesn't verify the SAN on a peer client certificate. If you don't specify SANs on the originating mesh endpoint, the SAN on the certificate provided by the terminating endpoint must match the mesh endpoint service discovery configuration. Since SPIRE vended certificates have a SPIFFE ID as a name, you must set the SAN since the name doesn't match the service discovery name.
Returns union: either
IResolvableorCfnVirtualNodePropsMixin.SubjectAlternativeNamesProperty- See Also:
-
getTrust
A reference to where to retrieve the trust chain when validating a peer’s Transport Layer Security (TLS) certificate.Returns union: either
IResolvableorCfnVirtualNodePropsMixin.TlsValidationContextTrustProperty- See Also:
-
builder
-