[BUG] OIDC // IPv6 // certificate subject name '*' does not match target hostname
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 45/100
- Tipo de issue
- Error
- Claridad
- Necesita aclaración
- Estado de actividad
- Activo
- Stack tecnológico
- docker
Línea de trabajo
No se nombra ningún archivo ni prueba. Empieza reproduciendo la solicitud de descubrimiento de OIDC en /.well-known/openid-configuration dentro de las versiones v26.05.1 y posteriores, comparando el comportamiento de curl -4 y curl -6 y los certificados devueltos. Se considera terminado cuando IPv6 llega al certificado correcto y el inicio de sesión de OIDC funciona sin la discrepancia de nombre de host.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Is there an existing issue for this?
- I have searched the existing issues
Current Behavior
When I try to log in with my OIDC provider, I get the following error message:
OIDC Discovery Error: HTTP request failed during discovery with error: cURL error 60: SSL: certificate subject name '*' does not match target hostname 'pocketid.server.de' (see https://curl.se/libcurl/c/libcurl-errors.html) for https://pocketid.server.de/.well-known/openid-configuration
It seems to have something to do with IPv6.
When I run this curl -4 -v https://pocketid.server.de command inside the container, I get the correct certificate
* Host pocketid.server.de:443 was resolved.
* IPv6: (none)
* IPv4: ...
* Trying ...:443...
* ALPN: curl offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* SSL Trust Anchors:
* CAfile: /etc/ssl/certs/ca-certificates.crt
* CApath: /etc/ssl/certs
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_128_GCM_SHA256 / X25519MLKEM768 / id-ecPublicKey
* ALPN: server accepted h2
* Server certificate:
* subject: CN=pocketid.server.de
* start date: May 28 10:38:49 2026 GMT
* expire date: Aug 26 10:38:48 2026 GMT
* issuer: C=US; O=Let's Encrypt; CN=E7
* Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA384
* Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using sha256WithRSAEncryption
* Certificate level 2: Public key type RSA (4096/152 Bits/secBits), signed using sha256WithRSAEncryption
* subjectAltName: "pocketid.server.de" matches cert's "pocketid.server.de"
* OpenSSL verify result: 0
* SSL certificate verified via OpenSSL.
* Established connection to pocketid.server.de (... port 443) from ... port 33744
* using HTTP/2
* [HTTP/2] [1] OPENED stream for https://pocketid.server.de/
* [HTTP/2] [1] [:method: GET]
* [HTTP/2] [1] [:scheme: https]
* [HTTP/2] [1] [:authority: pocketid.server.de]
* [HTTP/2] [1] [:path: /]
* [HTTP/2] [1] [user-agent: curl/8.21.0]
* [HTTP/2] [1] [accept: */*]
> GET / HTTP/2
> Host: pocketid.server.de
> User-Agent: curl/8.21.0
> Accept: */*
>
* Request completely sent off
But when I run this curl -6 -v https://pocketid.server.de command inside the container, I dont get the correct certificate
* Host pocketid.server.de:443 was resolved.
* IPv6: ....
* IPv4: (none)
* Trying ....
* ALPN: curl offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* SSL Trust Anchors:
* CAfile: /etc/ssl/certs/ca-certificates.crt
* CApath: /etc/ssl/certs
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / x25519 / RSASSA-PSS
* ALPN: server accepted h2
* Server certificate:
* subject: C=US; ST=CA; L=Carlsbad; O=Linuxserver.io; OU=LSIO Server; CN=*
* start date: Oct 10 06:22:39 2025 GMT
* expire date: Oct 8 06:22:39 2035 GMT
* issuer: C=US; ST=CA; L=Carlsbad; O=Linuxserver.io; OU=LSIO Server; CN=*
* Certificate level 0: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption
* SSL: certificate subject name '*' does not match target hostname 'pocketid.server.de'
* closing connection #0
curl: (60) SSL: certificate subject name '*' does not match target hostname 'pocketid.server.de'
More details here: https://curl.se/docs/sslcerts.html
curl failed to verify the legitimacy of the server and therefore could not
establish a secure connection to it. To learn more about this situation and
how to fix it, please visit the webpage mentioned above.
Problem only exists on Version > 26.05.1
v26.05.1 does not have this problem
- Lenguaje dominante
- Dockerfile
- Estrellas
- 1k
- Forks
- 139
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Issues similares
-
enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
canonical/paas-charm#368 · 1 comentario ·
-
enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
palladius/rails8-app-on-gcp#142 ·
-
addition to tracking list Abierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
StevenBlack/hosts#3256 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
corsairdev/corsair#1764 ·
-
oblt-aw/detector/security
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100