[Bug] No longer working
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 25/100
- Issue type
- Bug
- Clarity
- Needs clarification
- Activity status
- Stale
- Tech stack
- ios, objective-c
- Domain
- mobile-dev, security
Research direction
Start by reproducing the reported TrustKit 3.0.3 configuration on the iOS 16.2 Simulator and inspect the initialization log shown in the issue. Compare the TrustKit behavior with the related react-native-ssl-public-key-pinning integration. Done means requests to the pinned domain are blocked when invalid public-key hashes are configured.
Written by the indexing model from the issue text.
Description
Hi,
About 1-2 months ago, I had used this library through react-native-ssl-public-key-pinning to enforce SSL pinning in my company's app on a PoC branch, which worked as expected.
And just yesterday, I tried to install and apply the library again in a new branch, but now it does not block any request to pinned domain when using invalid keys.
I'm not sure if this was the issue with react-native-ssl-public-key-pinning or with the TrustKit, but the configuration used to initialize TrustKit looks supposedly correct. (I also opened an issue there)
Logs
(iOS to MacOS Console log)
=== TrustKit: Successfully initialized with configuration {
TSKPinnedDomains = {
"some-service.tech" = {
TSKDisableDefaultReportUri = 1;
TSKEnforcePinning = 1;
TSKIncludeSubdomains = 1;
TSKPublicKeyHashes = "{(\n {length = 32, bytes = 0x00000000 00000000 00000000 00000000 ... 00000000 00000000 },\n {length = 32, bytes = 0x04104104 10410410 41041041 04104104 ... 04104104 10410410 }\n)}";
kSKExcludeSubdomainFromParentPolicy = 0;
};
};
TSKSwizzleNetworkDelegates = 0;
}
Versions
TrustKit: 3.0.3
CocoaPods: 1.14.3
iOS: 16.2 (iPhone Simulator)
Thanks!
- Dominant language
- Objective-C
- Stars
- 2.1k
- Forks
- 381
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from datatheorem/TrustKit
-
Difficulty 4/5 3-5 days Newbie friendliness 30/100
datatheorem/TrustKit#360 ·
-
enhancement help wanted
Difficulty 4/5 3-5 days Newbie friendliness 35/100
datatheorem/TrustKit#341 · 1 comment ·
-
enhancement
Difficulty 3/5 1-2 days Newbie friendliness 48/100
datatheorem/TrustKit#340 · 2 comments ·
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
datatheorem/TrustKit#333 · 2 comments · 1 reaction ·
-
Difficulty 4/5 3-5 days Newbie friendliness 28/100
datatheorem/TrustKit#330 · 1 comment ·
All issues in datatheorem/TrustKit
Similar issues
-
api: remoteconfig
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
firebase/firebase-ios-sdk#16816 · 1 comment ·
Maintainers usually reply within 1 day
-
!
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
osmandapp/OsmAnd-iOS#5912 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-2 days Newbie friendliness 78/100
getsentry/sentry-cocoa#9219 · 1 comment ·
Maintainers usually reply within 1 day
-
feature-request
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
DataDog/dd-sdk-ios#3255 · 1 comment ·
Maintainers usually reply within 3 days
-
bug good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
repowise-dev/repowise#2785 ·
Maintainers usually reply within 1 day