ni / ni/nisystemlink-clients-python

SystemLink self-signed certificates multiple issues (Self-signed)

Open
#162 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
10
Forks
32
Avg merge
12h 42m
Merged PRs (30d)
2

Description

  1. Hostname mismatch: Certificate CN="myhost-self-signed" vs hostname="myhost"
  2. Missing keyCertSign usage (causes "Path length given without key usage keyCertSign" error)
  3. No Subject Alternative Names (modern SSL requires CN or SAN hostname match)
  4. Self-signed without proper trust store installation

Workaround:

Patch Python's ssl.create_default_context() to disable all certificate verification (SystemLink client calls ssl.create_default_context() internally)
bypassing HttpConfiguration(verify=False) and SL_CERT_PATH environment variables.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by tracing the SystemLink client calls to ssl.create_default_context and compare their behavior with HttpConfiguration(verify=False) and the SL_CERT_PATH environment variable. Done should address the reported hostname mismatch, keyCertSign usage, missing SANs, and trust-store handling without requiring certificate verification to be disabled.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.