hyperledger / hyperledger/fabric-chaincode-java
Incorrect parsing of SSL certificates and keys in ChaincodeBase in external launcher case
- Dominant language
- Java
- Stars
- 323
- Forks
- 210
- Avg merge
- 8h 1m
- Merged PRs (30d)
- 8
Description
ChaincodeBase attempts to parse SSL certificates and keys provided by an external launcher in the following manner:
```
final SslContext createSSLContext() throws IOException {
final byte[] ckb = Files.readAllBytes(Paths.get(this.tlsClientKeyPath));
final byte[] ccb = Files.readAllBytes(Paths.get(this.tlsClientCertPath));
return GrpcSslContexts.forClient().trustManager(new File(this.tlsClientRootCertPath))
.keyManager(new ByteArrayInputStream(Base64.getDecoder().decode(ccb)),
new ByteArrayInputStream(Base64.getDecoder().decode(ckb)))
.build();
}
```
This fails, because the certs deployed by the external builder are in PEM format, but the code attempts to Base64 decode them.
The fix is obvious, and I have used it successfully in testing (however, I would have to jump through a bunch of hoops to contribute it, so someone else should probably do it).
Contributor guide
Assessment
This issue has not been assessed yet.