nodejs / nodejs/node

--use-system-ca fails to start with bad OPENSSL_CONF set

Aperta
#63,256 3 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Lingua principale
JavaScript
Stelle
122k
Fork
37.4k
Merge medio
4g 3h
PR unite (30g)
272

Descrizione

Version

26.1.0 (also seen with 22.22.2)

Platform
Microsoft Windows NT 10.0.26200.0 x64

Only windows has been tested
Subsystem

No response

What steps will reproduce the bug?

In powershell

$env:OPENSSL_CONF="c:"
node --use-system-ca
How often does it reproduce? Is there a required condition?

This happens consistently when there is a bad OPENSSL_CONF variable set

What is the expected behavior? Why is that the expected behavior?

I would expect it to fail to load some certificates/configs, but succeed with the good items in the variables and launch correctly.

What do you see instead?
PS C:\Users\farad> $env:OPENSSL_CONF="c:"
PS C:\Users\farad> node --use-system-ca
C:\Users\farad\AppData\Local\fnm_multishells\11396_1778525811252\node.exe: OpenSSL configuration error:
44190000:error:80000005:system library:BIO_new_file:Input/output error:openssl\crypto\bio\bss_file.c:67:calling fopen(c:, rb)

And node exits

Additional information

Related #58990

I can appreciate this may be openssl behaviour that cannot be controlled.

In our application we are using nodejs binaries to spawn some child processes. We want to set this flag to make the use of corporate deployed certificates easier, but have encountered an application which sets OPENSSL_CONF to a directory and causes node to fail to start.

This also appears to affect binaries built with @yao/pkg

I have checked that this is not unique to being installed through fnm

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Direzione di ricerca

Inizia riproducendo il comando Windows PowerShell con OPENSSL_CONF impostato su "c:" e --use-system-ca. Il report non indica alcun file sorgente né alcun punto di ingresso dei test; segui la gestione all'avvio di queste opzioni in Node e verifica che un percorso di configurazione non valido non impedisca più l'avvio, mentre il caricamento dei certificati continui a funzionare con impostazioni valide.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
javascript, node.js
Ambito
security
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Tranquilla
Chiarezza
Abbastanza chiara
Idoneità per principianti
52/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.