SslStream indiscriminately uses ProtocolVersion TLS Alert for handshake failures

Open
#116,305 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
csharp

Research direction

Start in src/libraries/System.Net.Security/src/System/Net/Security/SslStream.IO.cs at lines 341-345 and trace how handshake failures select the TLS alert, especially on Windows. Determine how the existing error cases map to alerts; done means failures no longer indiscriminately produce ProtocolVersion alerts and instead use the closest matching alert.

Written by the indexing model from the issue text.

Description

area-System.Net.Security

Following code

https://github.com/dotnet/runtime/blob/49399d99e11d356c412c9fd2e25af3435abe2e13/src/libraries/System.Net.Security/src/System/Net/Security/SslStream.IO.cs#L341-L345

will make sure we send out a TLS alert when handshake fails to complete, however, (at least on Windows), this leads to indiscriminately sending out ProtocolVersion alerts even for other cases of errors, such as when the two parties cannot communicate because they don't possess a common cipher/sigalg, or because an invalid message was received. This may be misleading when attempting to debug TLS handshake errors.

We should attempt to reply with an alert that most closely resembles the type of error encountered.

Dominant language
C#
Stars
18.3k
Forks
5.6k
PR merge metrics
PR metrics pending

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from dotnet/runtime

All issues in dotnet/runtime

Similar issues

More C# issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.