--use-system-ca fails to start with bad OPENSSL_CONF set

Aperta
#63,256 3 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
52/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Tranquilla
Stack tecnologico
javascript, node.js
Ambito
security

Direzione di ricerca

Inizia riproducendo il comando Windows PowerShell con OPENSSL_CONF impostato su "c:" e --use-system-ca. Il report non indica alcun file sorgente né alcun punto di ingresso dei test; segui la gestione all'avvio di queste opzioni in Node e verifica che un percorso di configurazione non valido non impedisca più l'avvio, mentre il caricamento dei certificati continui a funzionare con impostazioni valide.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Version

26.1.0 (also seen with 22.22.2)

Platform
Microsoft Windows NT 10.0.26200.0 x64

Only windows has been tested
Subsystem

No response

What steps will reproduce the bug?

In powershell

$env:OPENSSL_CONF="c:"
node --use-system-ca
How often does it reproduce? Is there a required condition?

This happens consistently when there is a bad OPENSSL_CONF variable set

What is the expected behavior? Why is that the expected behavior?

I would expect it to fail to load some certificates/configs, but succeed with the good items in the variables and launch correctly.

What do you see instead?
PS C:\Users\farad> $env:OPENSSL_CONF="c:"
PS C:\Users\farad> node --use-system-ca
C:\Users\farad\AppData\Local\fnm_multishells\11396_1778525811252\node.exe: OpenSSL configuration error:
44190000:error:80000005:system library:BIO_new_file:Input/output error:openssl\crypto\bio\bss_file.c:67:calling fopen(c:, rb)

And node exits

Additional information

Related #58990

I can appreciate this may be openssl behaviour that cannot be controlled.

In our application we are using nodejs binaries to spawn some child processes. We want to set this flag to make the use of corporate deployed certificates easier, but have encountered an application which sets OPENSSL_CONF to a directory and causes node to fail to start.

This also appears to affect binaries built with @yao/pkg

I have checked that this is not unique to being installed through fnm

Lingua principale
JavaScript
Stelle
122k
Fork
37.4k
Merge medio
4g 3h
PR unite (30g)
272

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di nodejs/node

Tutte le issue di nodejs/node

Issue simili

Altre issue su JavaScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.