Repository navigation
TLS fails reading self-signed certificate on node 4.2.5+ #5100
Description
Activity
@diegossilveira I tested with the v4 branch, so quite possible that that is the reason.
there were three commits that landed on 4.2.5 that touched TLS. Perhaps @indutny has some insight
- addedtlsIssues and PRs related to the tls subsystem.Issues and PRs related to the tls subsystem.ltsIssues and PRs related to Long-Term Support (LTS) releases.Issues and PRs related to Long-Term Support (LTS) releases.
on Feb 5, 2016 /cc @jasnell
- addedconfirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.
on Feb 5, 2016 It is definitely caused by that PFX commit. Reverting it fixes the issue. Will look more deeply into it.
This is where the issue comes from: a2c1799#diff-801e3948990f4965a8ea4aca4a423864L928 . Going to investigate the best way to fix it right now.
Ok, so I have several thoughts about this. There are two conflicting things in my opinion:
- API stability
- Sanity of the
pfxoption intls.createServer/tls.connect
From stability point of view, we should not really break anything unless there is security need for this, and that commit is absolutely breaking change (as we have just figured out).
From sanity point of view, there is no way in PKCS12 (
pfx) to distinguish between regular server/client certs and CA certs for validating the other side. It seems to be pretty unsafe to me, but this is the way it has been implemented and documented for a long time.@dbkup is what
pfxcurrently provides exactly what you need from it? Do you expect it to use the same certs for both client validation and sever authorization?cc @nodejs/crypto @nodejs/ctc @nodejs/lts
Should be fixed by #5109
OK, let's get this fixed in the next LTS release after next week's security
release. Should be maybe a week later. I'm definitely thinking we need a RC
cycle tho for all LTS releases moving forward.
On Feb 5, 2016 2:34 PM, "Fedor Indutny" notifications@github.com wrote:Should be fixed by #5109 #5109
—
Reply to this email directly or view it on GitHub
#5100 (comment).12 remaining items
- added 2 commits that reference this issue
on Mar 2, 2016 - added 2 commits that reference this issue
on Apr 2, 2016 - added a commit that references this issue
on Mar 18, 2018 - added 2 commits that reference this issue
on Mar 20, 2018 - added a commit that references this issue
on Dec 3, 2018
I'm having an issue with ssl certificate validation using the
tlsmodule. The server is started with:The client:
My issue is that I get
tlsSocket.authorizationErrorSELF_SIGNED_CERT_IN_CHAIN on v4.2.5+ but not on older versions. Here's my output on a Windows machine, but the same happens on an Ubuntu server.The
auth->line is printed to console with thetlsSocket.authorizationErrorparameter when a client connects. In the case of a successful connect this field isnull.Tested down to 0.12.9, all versions read the certificate without issues.