2ccd11b68c709e6fb254c844755e46124ac1bc0a
Phase 0001d of issue 0001. embeddednats grows a ServerConfig with an optional TLS config; the client can pin the bus's self-signed CA via Options.TLS built from busauth.LoadCATLSConfig. deploy/tls/generate-certs.sh mints the CA and a server cert (SAN: public IP, WG IP, om, localhost) — only the public ca.crt is versioned, private keys are gitignored. A client trusting the CA completes the handshake; one without it fails. TLS stays off until phase 0001e wires it in. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Description
Synced from fn_registry
Languages
Go
94.2%
TypeScript
3.1%
Shell
2.6%