Can we get DEBUG loggin from the OpenSSL library?
Los mantenedores suelen responder en 1 día
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 28/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bastante claro
- Estado de actividad
- Estancado
- Área
- cryptography, security
Línea de trabajo
Comienza con la salida de depuración de OpenSSL referenciada en crypto/x509/t_x509.c y compárala con el comportamiento de OpenSSL::debug de Ruby. Revisa el ejemplo de verify_callback y store_context y determina después si un indicador expuesto a Ruby puede proporcionar detalles equivalentes del certificado sin callbacks a nivel de aplicación. Se considera terminado cuando la interfaz propuesta y su comportamiento de registro esperado están definidos y probados.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Hi,
Problem
As a developer I would like to see (DEBUG) logging from OpenSSL. We have a Ruby application that connects to Amazon Cloudfront to retrieve a file. This runs through a network outside of our control containing NAT gateways, proxies, etc.
This works 99% of the time, but Intermittently we get a self signed certificate error:
OpenSSL::SSL::SSLError (SSL_connect returned=1 errno=0
peeraddr=18.66.171.65:443 state=error: certificate verify failed
(self signed certificate in certificate chain))
But it doesn't show WHICH certificate (or subject, fignerprint, ...) is being seen.
Question / Request
Ideally we would have a ruby OpenSSL flag that instructs OpenSSL to do its (DEBUG) logging so we can get this information. I can see OpenSSL is logging the desired information in:
Is it possible to get the Ruby app to log this information?
I have found OpenSSL::debug=true, but this only seems to trigger debug logging done in this Ruby Gem.
In java we have -Djava.net.debug=ssl, but I realize that is not using OpenSSL underneath.
Alternative
I have found a way to get Ruby to log the self-signed certificate that is being seen in Ruby via https://github.com/mislav/ssl-tools/blob/master/doctor.rb. Something along these lines, where the store_context contains the failed certificat:
http.verify_callback = lambda { |verify_ok, store_context|
if !verify_ok
failed_cert = store_context.current_cert
failed_cert_reason = "%d: %s" % [ store_context.error, store_context.error_string ]
end
verify_ok
}
This is not ideal as it requires code changes in our Ruby apps, which is using httparty as a wrapper. Also we would be replicating logging that is already done by OpenSSL.
The fact that this SSL Docter script exists seems to confirm there is no Ruby OpenSSL::xxx flag to achieve this?
Would it be possible to implement such a flag? Is there an alternative way to achieve the same?
- Lenguaje dominante
- C
- Estrellas
- 276
- Forks
- 200
- Merge medio
- 15 h 27 min
- PR fusionados (30 d)
- 7
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de ruby/openssl
-
Explicit check for true instead of true-ish in OpenSSL::BN.randPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
ruby/openssl#1116 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 3/5 1-2 días Aptitud para principiantes 55/100
ruby/openssl#1118 · 4 comentarios ·
Los mantenedores suelen responder en 1 día
-
Expose XOFs like SHAKE128 and SHAKE256Posiblemente ocupada @rhenium la tomó hace 90 días. Abierto
Dificultad 4/5 3-5 días Aptitud para principiantes 48/100
ruby/openssl#1082 · 4 comentarios ·
Los mantenedores suelen responder en 1 día
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
ruby/openssl#1075 · 4 comentarios ·
Los mantenedores suelen responder en 1 día
-
Unchecked *_set_* callsPosiblemente ocupada @ndossche la tomó hace 160 días. Abierto
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
ruby/openssl#1038 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de ruby/openssl
Issues similares
-
CVE-2026-18839 popt: size_t underflow in `singleOptionHelp`Posiblemente ocupada @pmatilai la tomó hace 34 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
rpm-software-management/popt#143 ·
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 85/100
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 85/100
libretro/mupen64plus-libretro-nx#663 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
dkfans/keeperfx#5415 · 1 comentario ·
Los mantenedores suelen responder en 1 día