diff --git a/changelog.d/12435.misc b/changelog.d/12435.misc new file mode 100644 index 000000000000..3a6845257388 --- /dev/null +++ b/changelog.d/12435.misc @@ -0,0 +1 @@ +Enable certificate checking during complement tests. diff --git a/docker/complement/conf-workers/workers-shared.yaml b/docker/complement/conf-workers/workers-shared.yaml index cdadb736f6ff..8b6987037715 100644 --- a/docker/complement/conf-workers/workers-shared.yaml +++ b/docker/complement/conf-workers/workers-shared.yaml @@ -7,11 +7,6 @@ bcrypt_rounds: 4 ## Federation ## -# disable verification of federation certificates -# -# TODO: Figure out why this is still needed even though we are making use of the custom CA -federation_verify_certificates: false - # trust certs signed by Complement's CA federation_custom_ca_list: - /complement/ca/ca.crt diff --git a/docker/complement/conf/homeserver.yaml b/docker/complement/conf/homeserver.yaml index be53c4aa2e33..c9d6a312401a 100644 --- a/docker/complement/conf/homeserver.yaml +++ b/docker/complement/conf/homeserver.yaml @@ -41,13 +41,6 @@ database: ## Federation ## - -# disable verification of federation certificates -# -# TODO: this is temporary; see -# https://github.com/matrix-org/synapse/issues/11803 -federation_verify_certificates: false - # trust certs signed by the complement CA federation_custom_ca_list: - /complement/ca/ca.crt