dotnet / dotnet/yarp

Hostname validation against server's certificate for HTTPs Ingress backends

Open
#2,137 2 comments 2 reactions 0 assignees View on GitHub
Kubernetes Ingress Controller Type: Idea
Dominant language
C#
Stars
9.6k
Forks
933
Avg merge
12d 18h
Merged PRs (30d)
2

Description

When Ingress backend uses HTTPs request forwarding fails with something like:
```
System.Net.Http.HttpRequestException: 'The SSL connection could not be established, see inner exception.'
AuthenticationException: The remote certificate is invalid according to the validation procedure: RemoteCertificateNameMismatch
```

This happens because the ingress controller resolves the backend service to a set of endpoints which are IP addresses. `ClusterConfig.Destinations` in turn has addresses with just IPs. When forwarding the request there is no information about the destination hostname and therefore server's certificate validation fails.

There are couple workarounds:
1. Use `HttpClientConfig.DangerousAcceptAnyServerCertificate`
2. Define a transform on the ingress rule to set `Host` header:
```
annotations:
yarp.ingress.kubernetes.io/transforms: |
- RequestHeader: Host
Set: "my.backend.hostname"
```

I'm creating this for awareness for others running into the same issue and to discuss if there is anything can be done for it to just work.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.