HTTPS proxy connection (p_use_ssl/proxy_use_ssl) does not verify the proxy's certificate
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 55/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Tranquilo
- Stack tecnológico
- ruby
- Área
- networking, security
Línea de trabajo
Comienza en lib/net/http.rb#connect, específicamente en la rama @proxy_use_ssl que crea el SSLSocket del proxy. Compara su configuración con la conexión TLS al destino y determina cómo deben configurarse por separado la verificación del certificado del proxy y la comprobación del nombre de host. Se considera terminado cuando el certificado del proxy se verifica de forma predeterminada antes de enviar Proxy-Authorization, y se cubren todos los ajustes de verificación necesarios.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
When connecting to a destination over TLS through a TLS proxy (an "HTTPS proxy"), enabling p_use_ssl encrypts the client→proxy hop but does not authenticate the proxy's certificate. The proxy TLS socket is built with no SSLContext and no post-connection check, so it defaults to VERIFY_NONE. This makes the proxy hop MITM-able, which matters because the Proxy-Authorization (Basic) credential is written over that socket in the CONNECT request.
Setup
Either of the documented ways to enable a TLS proxy:
proxy = Net::HTTP.Proxy('proxy.example.com', 8080, 'user', 'pass', true) # 5th arg -> @proxy_use_ssl
http = proxy.new('login.example.com', 443)
http.use_ssl = true
# ...or Net::HTTP.new(addr, port, p_addr, p_port, p_user, p_pass, p_no_proxy, true)
http.get('/')
What happens
In Net::HTTP#connect, when @proxy_use_ssl is set, the proxy socket is wrapped as:
proxy_sock = OpenSSL::SSL::SSLSocket.new(s) # no SSLContext passed
ssl_socket_connect(proxy_sock, @open_timeout)
# ... then CONNECT + "Proxy-Authorization: Basic <creds>" is written to proxy_sock
SSLSocket.new(s) with no context uses a default context (verify_mode effectively VERIFY_NONE), and there is no post_connection_check on proxy_sock— the only post_connection_check in connect targets @address (the destination). So:
- The destination cert is verified (via
@ssl_context+post_connection_check(@address)). ✅ - The proxy cert is neither verified nor hostname-checked. ❌
A MITM on the client→proxy path can therefore present any certificate, terminate the TLS, and read the Proxy-Authorization credential — the same credential exposure that enabling proxy TLS is meant to prevent.
Expected
The proxy TLS connection should verify the proxy certificate by default (use an SSLContext with VERIFY_PEER and run post_connection_check against the proxy host), consistent with how the destination connection is verified. At minimum there should be a way to supply verification settings (CA store, verify_mode, hostname) for the proxy connection distinct from the destination's.
Environment
- Ruby 4.0.5
- net-http 0.9.1
- Reproduced by reading
lib/net/http.rb#connect(theif @proxy_use_sslbranch) — the proxy SSLSocket is built without a context and gets nopost_connection_check.
Related
- jnunemaker/httparty#839 tracks a separate, complementary gap: HTTParty can't even set p_use_ssl (it passes only 6 of
Net::HTTP.new's proxy args). This net-http issue is about the flag existing but not verifying the proxy cert.
- Lenguaje dominante
- Ruby
- Estrellas
- 148
- Forks
- 95
- Merge medio
- 10 h 54 min
- PR fusionados (30 d)
- 4
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de ruby/net-http
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 83/100
-
Dificultad 4/5 3-5 días Aptitud para principiantes 55/100
-
bug documentation
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
-
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
Todos los issues de ruby/net-http
Issues similares
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
-
バグ
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
-
Version bump for OpenVox 9 Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
voxpupuli/puppet-epel#186 · 1 comentario ·
-
external_created_at is no longer used for the message timestamp since the new message UI (v4.4.0) AbiertoBug Frontend
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100