github / github/codeql

Entra ID as SAML IdP Causes CodeQL to Fail with Self-Signed Certificate Found in Certificate Chain

オープン
#17,082 コメント 8 件 リアクション 1 件 担当者 0 名 GitHub で見る
question
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

### Environment

- GHES 3.13.0 on Azure VM STIGd to 98% (working fine)
- EntraID SAML setup for GitHub
**NOTE: Tried OIDC however GitHub 3.13.0 goes to the Azure commercial endpoints and not the government ones.**
**NOTE: If trying to send GH audit to EventHub, same issue. GH 3.13.0 defaults to commercial endpoints and not government**
- Configured SAML on GH and verify working fine including hydrating additional claims for GH admins and GH users

### Expectation

- CodeQL executes honoring the certificate chain presented by the GitHub server for CodeQL

### Problem

- Self-Signed certificate found in chain:
![image](https://github.com/user-attachments/assets/391c564a-d21a-4133-ae2a-88ff3f23a842)

### Additional Comments / Notes

Cross-Reference for some additional context: https://security.stackexchange.com/questions/146132/self-signed-certificate-for-a-idp-initiated-saml-sso

When executing on my Windows 2022 CodeQL Server:

`.\openssl s_client -showcerts -connect :443`

shows the self-signed certificate in the chain:

```
Server certificate
subject=*****redacted*****, CN=
issuer=*****redacted***** Pointing to VALID root and in certificate store and verifed *****
---
No client certificate CA names sent
Peer signing digest: *****redacted*****
Peer signature type: *****redacted*****
Server Temp Key: *****redacted*****
---
SSL handshake has read 4630 bytes and written 395 bytes
Verification error: self-signed certificate in certificate chain
---
New, TLSv1.3, Cipher is *****redacted*****
Server public key is *****redacted*****
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 19 (self-signed certificate in certificate chain)
---
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol : TLSv1.3
Cipher : *****redacted*****
Session-ID:*****redacted*****
Session-ID-ctx:
Resumption PSK: *****redacted*****
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 7200 (seconds)
TLS session ticket: *****redacted*****

Start Time:*****redacted*****
Timeout : 7200 (sec)
Verify return code: 19 (self-signed certificate in certificate chain)
Extended master secret: no
Max Early Data: 0
---
```

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。