07th-mod / 07th-mod/python-patcher

SSL/TLS Errors Index Page

未關閉 適合新手
#214 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
JavaScript
星號
214
分支
12
PR 合併指標
30 天內沒有已合併 PR

描述

This page indexes all the SSL/TLS problems we've had, and also records the recent SSL/TLS problem we've had.

### Recent SSL/TLS issue

Recently, two MacOS 10 users had an SSL error where, even though we had implemented the CURL fallback, even CURL was using certificates which wouldn't download from our 07th-mod site.

To fix this, I sent one user a version of the installer which uses a bundled certificate, if all else fails (as suggsted in https://github.com/07th-mod/python-patcher/issues/80).

### Further Explanation

Previously, we only used CURL (set the CURL executable) if it could download from the 07th-mod website.

Now, we set the CURL executable as long as it is available (even if it cannot download).

Then, we try to figure out which CURL certificate we should use, by trying each one:
- Use whatever the default is (no argument passed to CURL)
- Use any certificates found on the system (currently we only find certs on Linux though)
- Use the bundled certificate

The installer will try both the 07th-mod and github websites, and if a cert works with both then it chooses that one for the rest of the install.

The bundled certificate is retrieved from the CURL website https://curl.se/docs/caextract.html . It will be updated each time the installer is rebuilt. We would need to re-build the installer periodically as the certs would eventually expire, though, but I guess this is a last resort anyway.

### Known Issues

- Testing the certifcate requires/uses only CURL
- Currently Python's URLOpen does not use the chosen certificate. But wherever it is used in the installer, we have a CURL fallback.
- Also, while this certificate is also passed into Aria2, I noticed that on my Windows machine it doesn't like the certificate format. But on the MacOS logs, it appears to use the certificate.

### List of previous TLS/SSL issues

- https://github.com/07th-mod/python-patcher/issues/190
- https://github.com/07th-mod/python-patcher/issues/189
- https://github.com/07th-mod/python-patcher/issues/80
- https://github.com/07th-mod/python-patcher/pull/78
- https://github.com/07th-mod/python-patcher/issues/77
- https://github.com/07th-mod/python-patcher/issues/60

貢獻指南

這個儲存庫沒有索引到貢獻指南

研究方向

這是 SSL/TLS 問題的索引頁。閱讀連結的 issue(190、189、80、78、77、60)以了解歷史。安裝程式碼處理憑證回退邏輯;請查找 curl 的使用和憑證捆綁。任務是維護此頁面作為摘要,並在新問題出現時添加它們。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
python, shell
領域
cli, security
Issue 類型
文件
難度
1/5
預估耗時
1 小時以內
活躍度
停滯
描述清晰度
描述清楚
新手友好度
75/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。