Entra ID as SAML IdP Causes CodeQL to Fail with Self-Signed Certificate Found in Certificate Chain
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 15 小時
- 30 天內合併 PR
- 141
描述
### Environment
- GHES 3.13.0 on Azure VM STIGd to 98% (working fine)
- EntraID SAML setup for GitHub
**NOTE: Tried OIDC however GitHub 3.13.0 goes to the Azure commercial endpoints and not the government ones.**
**NOTE: If trying to send GH audit to EventHub, same issue. GH 3.13.0 defaults to commercial endpoints and not government**
- Configured SAML on GH and verify working fine including hydrating additional claims for GH admins and GH users
### Expectation
- CodeQL executes honoring the certificate chain presented by the GitHub server for CodeQL
### Problem
- Self-Signed certificate found in chain:

### Additional Comments / Notes
Cross-Reference for some additional context: https://security.stackexchange.com/questions/146132/self-signed-certificate-for-a-idp-initiated-saml-sso
When executing on my Windows 2022 CodeQL Server:
`.\openssl s_client -showcerts -connect :443`
shows the self-signed certificate in the chain:
```
Server certificate
subject=*****redacted*****, CN=
issuer=*****redacted***** Pointing to VALID root and in certificate store and verifed *****
---
No client certificate CA names sent
Peer signing digest: *****redacted*****
Peer signature type: *****redacted*****
Server Temp Key: *****redacted*****
---
SSL handshake has read 4630 bytes and written 395 bytes
Verification error: self-signed certificate in certificate chain
---
New, TLSv1.3, Cipher is *****redacted*****
Server public key is *****redacted*****
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 19 (self-signed certificate in certificate chain)
---
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol : TLSv1.3
Cipher : *****redacted*****
Session-ID:*****redacted*****
Session-ID-ctx:
Resumption PSK: *****redacted*****
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 7200 (seconds)
TLS session ticket: *****redacted*****
Start Time:*****redacted*****
Timeout : 7200 (sec)
Verify return code: 19 (self-signed certificate in certificate chain)
Extended master secret: no
Max Early Data: 0
---
```
貢獻指南
研究方向
No repository file or test is identified; begin with the Entra ID SAML and GHES 3.13.0 setup described, then reproduce the Windows 2022 CodeQL Server check using the provided openssl s_client command. Done means determining why the self-signed certificate appears in the chain and establishing that CodeQL honors the GitHub server's valid certificate chain.
由索引模型根據 Issue 內容生成。
評估
- 領域
- security
- Issue 類型
- 缺陷
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 活躍度
- 停滯
- 描述清晰度
- 需要釐清
- 新手友好度
- 25/100