How to use `new tls.TLSSocket(...)` to establish a secure connection?
Nessuno ha ancora preso questa issue.
- Lingua principale
- JavaScript
- Stelle
- 122k
- Fork
- 37.3k
- Merge medio
- 4g 2h
- PR unite (30g)
- 283
Descrizione
Affected URL(s)
https://nodejs.org/docs/latest-v18.x/api/tls.html
Description of the problem
What is the correct, non-deprecated way to use the new tls.TLSSocket(...) constructor to establish a secure connection? Context: https://github.com/typelevel/fs2/security/advisories/GHSA-2cpx-6pqp-wf35
According to two unmerged docs PRs, when directly calling new tls.TLSSocket(...) it is the user's responsibility to validate peer certificates and identity.
In https://github.com/nodejs/node/pull/10846 it says:
Warning: When directly constructing a
tls.TLSSocketinstead of using
[tls.connect()][] it is the caller's responsibility to:
- manage the lifetime of the the underlying socket, including connecting it;
- validate the peer certificate and identity, see the [
'secure'][] event.
Before using the connection, the user must make the following
checks or the connection should be considered completely insecure:
- Verify that the peer certificate is valid, see [
ssl.verifyError()][].- Verify that the peer certificate is for the expected host, see
[tls.checkServerIdentity()][] and [tls.TLSSocket.getPeerCertificate()][].
In https://github.com/nodejs/node/pull/23915 it says:
It is important to remember, however,
that it is the caller's responsibility to manage the lifecycle of the provided
net.Socket, including establishing the connection and validating peer
certificates and identity. See the ['secure'][] event.
And includes an example:
tlsSocket.on('secure', function() {
const err = this.verifyError() ||
tls.checkServerIdentity(hostname, this.getPeerCertificate());
if (err)
this.destroy(err);
});
Both PRs demonstrate how to do this validation, but require use of:
- The
'secure'event. In the current Node.js documentation, the only mention of'secure'is under the deprecatedtls.SecurePair, and is itself deprecated. It is also not clear that the'secure'event is also emitted ontls.TLSSocket.
https://nodejs.org/docs/latest-v18.x/api/tls.html#event-secure tlsSocket.ssl.verifyError(), which does not appear at all in the current documentation. Furthermore, according to https://github.com/nodejs/node/pull/840#issuecomment-74343250tlsSocket.sslis a "legacy property".
Note that the described validation steps appear to be consistent with internal use
https://github.com/nodejs/node/blob/5fbf33ef8641cf57bfbb7f0c87f83447c44266b8/lib/_tls_wrap.js#L1106
https://github.com/nodejs/node/blob/5fbf33ef8641cf57bfbb7f0c87f83447c44266b8/lib/_tls_wrap.js#L1044-L1055
This leaves me with two concerns:
- The current documentation does not indicate that using
new tls.TLSSocket(...)by itself does not result in a secure connection. - As far as I can tell it is impossible to use
new tls.TLSSocket(...)to establish a secure connection without relying on APIs that are undocumented, deprecated, and/or legacy.
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Direzione di ricerca
Inizia dalla documentazione TLS v18 per tls.TLSSocket, l’evento 'secure' e le sezioni collegate di lib/_tls_wrap.js. Confronta le API documentate con l’esempio di convalida che usa verifyError(), tls.checkServerIdentity() e getPeerCertificate(). Il lavoro è completo quando la documentazione spiega chiaramente un modo supportato e non deprecato per stabilire e convalidare una connessione sicura, oppure documenta esplicitamente la limitazione.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- javascript, node.js
- Ambito
- documentation, security
- Tipo di issue
- Documentazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Stato di attività
- Attiva
- Chiarezza
- Abbastanza chiara
- Idoneità per principianti
- 50/100