Verify server certificates
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 202
- Forks
- 22
- Avg merge
- 6h 8m
- Merged PRs (30d)
- 7
Description
This is necessary to prevent trivial man-in-the-middle attacks on clients. However, care is necessary to ensure servers can be easily hosted on a LAN and from servers that lack a domain name. Ideally we'll likely want a combination of paradigms:
- Traditional PKI for servers with real domain names
- Trust-on-first-use for WAN IP addresses
- Something else for LAN IP addresses, since TOFU is likely to be too onerous on addresses that will be frequently reassigned. Maybe disable verification and display a fingerprint that can be manually verified if desired?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue identifies no files, tests, or entry points. First locate the client connection and certificate-handling paths, then clarify the verification policy for domain names, WAN IP addresses, and LAN IP addresses. Done should include an agreed approach that prevents trivial man-in-the-middle attacks while supporting the hosting cases described.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- networking, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100