GitHub
02/23/2025, 12:35 PM--tls_server_certs and we can simply omit providing a file and this flag. When Osquery attempts to connect to osctrl it will use the OSes root cert store to verify the cert.
In addition, since ACM certs are only valid for 1 year this means we don't have to manage rotating secrets on clients.
jmpsec/osctrlGitHub
02/23/2025, 12:35 PM