github / github/codeql

Entra ID as SAML IdP Causes CodeQL to Fail with Self-Signed Certificate Found in Certificate Chain

Đang mở
#17,082 8 bình luận 1 reaction 0 người được giao Xem trên GitHub
question
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

### Environment

- GHES 3.13.0 on Azure VM STIGd to 98% (working fine)
- EntraID SAML setup for GitHub
**NOTE: Tried OIDC however GitHub 3.13.0 goes to the Azure commercial endpoints and not the government ones.**
**NOTE: If trying to send GH audit to EventHub, same issue. GH 3.13.0 defaults to commercial endpoints and not government**
- Configured SAML on GH and verify working fine including hydrating additional claims for GH admins and GH users

### Expectation

- CodeQL executes honoring the certificate chain presented by the GitHub server for CodeQL

### Problem

- Self-Signed certificate found in chain:
![image](https://github.com/user-attachments/assets/391c564a-d21a-4133-ae2a-88ff3f23a842)

### Additional Comments / Notes

Cross-Reference for some additional context: https://security.stackexchange.com/questions/146132/self-signed-certificate-for-a-idp-initiated-saml-sso

When executing on my Windows 2022 CodeQL Server:

`.\openssl s_client -showcerts -connect :443`

shows the self-signed certificate in the chain:

```
Server certificate
subject=*****redacted*****, CN=
issuer=*****redacted***** Pointing to VALID root and in certificate store and verifed *****
---
No client certificate CA names sent
Peer signing digest: *****redacted*****
Peer signature type: *****redacted*****
Server Temp Key: *****redacted*****
---
SSL handshake has read 4630 bytes and written 395 bytes
Verification error: self-signed certificate in certificate chain
---
New, TLSv1.3, Cipher is *****redacted*****
Server public key is *****redacted*****
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 19 (self-signed certificate in certificate chain)
---
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol : TLSv1.3
Cipher : *****redacted*****
Session-ID:*****redacted*****
Session-ID-ctx:
Resumption PSK: *****redacted*****
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 7200 (seconds)
TLS session ticket: *****redacted*****

Start Time:*****redacted*****
Timeout : 7200 (sec)
Verify return code: 19 (self-signed certificate in certificate chain)
Extended master secret: no
Max Early Data: 0
---
```

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.