ni / ni/nisystemlink-clients-python
SystemLink self-signed certificates multiple issues (Self-signed)
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 10
- Forks
- 32
- Avg merge
- 12h 42m
- Merged PRs (30d)
- 2
Description
- Hostname mismatch: Certificate CN="myhost-self-signed" vs hostname="myhost"
- Missing keyCertSign usage (causes "Path length given without key usage keyCertSign" error)
- No Subject Alternative Names (modern SSL requires CN or SAN hostname match)
- Self-signed without proper trust store installation
Workaround:
Patch Python's ssl.create_default_context() to disable all certificate verification (SystemLink client calls ssl.create_default_context() internally)
bypassing HttpConfiguration(verify=False) and SL_CERT_PATH environment variables.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing the SystemLink client calls to ssl.create_default_context and compare their behavior with HttpConfiguration(verify=False) and the SL_CERT_PATH environment variable. Done should address the reported hostname mismatch, keyCertSign usage, missing SANs, and trust-store handling without requiring certificate verification to be disabled.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100