python / python/cpython

SSLSocket.getpeercert returns none if cert isn't valid

Aberta
#122,962 0 comentários 3 reações 0 responsáveis Ver no GitHub

Ninguém assumiu esta issue ainda.

stdlib topic-SSL type-bug
Linguagem predominante
Python
Estrelas
77.2k
Forks
36k
Métricas de merge de PRs
Métricas de PR pendentes

Descrição

Bug report

Bug description:

It's possible I'm misunderstanding, but it seems the documentation around SSLSocket.getpeercert is incorrect and/or the function is bugged. This was run on Fedora 40 with python 3.12.5. I'm trying to bypass DNS and pull the SSL cert straight from an IP for a specific set of Hosts.

the docs I'm referencing: https://docs.python.org/3/library/ssl.html#ssl.SSLSocket.getpeercert

Site and HostIP are variables representing a site URL and a Apache server's direct IP address. This is inside a function call.

the code:

	#empty cert info dict
	SiteCertInfo = {}

	#create SSL context and socket
	#this overrides "DNS" so we can pull the SSL cert as it is on the server
	sslContext = ssl.create_default_context()
	sslSock = socket.socket()
	sslConn = sslContext.wrap_socket(sslSock, server_hostname=Site)

	#try the connection
	try:
		sslConn.connect((HostIp, 443))
 
	#ssl cert can't be verified / doesn't match
	except ssl.SSLCertVerificationError as ex:
		#show error reasons
		print(Site + " site SSL did not verify. reason: " + ex.verify_message, file=sys.stderr)

		#continue
		pass
	


	#pull the cert from the connection
	sslCert = sslConn.getpeercert()

The error:

    sslCert = sslConn.getpeercert()
              ^^^^^^^^^^^^^^^^^^^^^
  File "/usr/lib64/python3.12/ssl.py", line 1129, in getpeercert
    return self._sslobj.getpeercert(binary_form)
           ^^^^^^^^^^^^^^^^^^^^^^^^
AttributeError: 'NoneType' object has no attribute 'getpeercert'

The issue:
The documentation states "for a client SSL socket, the server will always provide a certificate, regardless of whether validation was required;" I'm reading that as my python "client" connecting to the remote server should always get a cert even if it fails validation.

However, if the certificate is expired I'm catching the error and continuing on via the pass call. The sslConn.getpeercert() call fails as sslConn is None. If I don't catch the error then it just fails as normal.

If I try and by-pass validation by doing:

	sslContext = ssl.SSLContext(protocol = ssl.PROTOCOL_TLS_CLIENT)
	sslContext.check_hostname = False
	sslContext.verify_mode = ssl.CERT_NONE
	sslContext.set_default_verify_paths()

This just fails and pulls a "empty" dict for sslCert. If I set verify_mode back to CERT_REQUIRED I'm back to square one.

So, there doesn't seem to be a way to "catch" the validation error, but still continue to load the cert if the cert is expired or to disable validation via CERT_NONE and still pull the cert data and manually "validate" it.

CPython versions tested on:

3.12

Operating systems tested on:

Linux

Guia de contribuição

Abrir o guia de contribuição

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Direção de pesquisa

Comece pelo comportamento documentado de ssl.SSLSocket.getpeercert e pelas configurações de verificação de SSLContext; em seguida, reproduza o fluxo de conexão relatado usando um certificado expirado e CERT_NONE. Compare o estado do socket após SSLCertVerificationError com o resultado de getpeercert(binary_form=True). O trabalho estará concluído quando for estabelecido se o comportamento é um bug de implementação ou um problema de documentação e for adicionado o teste de regressão correspondente ou um esclarecimento na documentação.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
python
Domínio
networking, security
Tipo de issue
Bug
Dificuldade
4/5
Tempo estimado
3-5 dias
Status de atividade
Estagnada
Clareza
Razoavelmente clara
Facilidade para iniciantes
35/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.