Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

[BUG] OIDC // IPv6 // certificate subject name '*' does not match target hostname

Ouverte
#296 3 commentaires 0 réactions 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

Évaluation

Difficulté
4/5
Temps estimé
3-5 jours
Accessibilité débutants
45/100
Type d'issue
Bug
Clarté
À clarifier
Activité
Active
Stack technique
docker

Piste de recherche

Aucun fichier ni test n’est nommé. Commencez par reproduire la requête de découverte OIDC à l’adresse /.well-known/openid-configuration dans les versions v26.05.1 et ultérieures, en comparant le comportement de curl -4 et curl -6 ainsi que les certificats renvoyés. C’est terminé lorsque IPv6 atteint le bon certificat et que la connexion OIDC réussit sans l’incompatibilité de nom d’hôte.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

Is there an existing issue for this?
  • I have searched the existing issues
Current Behavior

When I try to log in with my OIDC provider, I get the following error message:

 OIDC Discovery Error: HTTP request failed during discovery with error: cURL error 60: SSL: certificate subject name '*' does not match target hostname 'pocketid.server.de' (see https://curl.se/libcurl/c/libcurl-errors.html) for https://pocketid.server.de/.well-known/openid-configuration

It seems to have something to do with IPv6.

When I run this curl -4 -v https://pocketid.server.de command inside the container, I get the correct certificate

* Host pocketid.server.de:443 was resolved.
* IPv6: (none)
* IPv4: ...
*   Trying ...:443...
* ALPN: curl offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* SSL Trust Anchors:
*   CAfile: /etc/ssl/certs/ca-certificates.crt
*   CApath: /etc/ssl/certs
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_128_GCM_SHA256 / X25519MLKEM768 / id-ecPublicKey
* ALPN: server accepted h2
* Server certificate:
*   subject: CN=pocketid.server.de
*   start date: May 28 10:38:49 2026 GMT
*   expire date: Aug 26 10:38:48 2026 GMT
*   issuer: C=US; O=Let's Encrypt; CN=E7
*   Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA384
*   Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using sha256WithRSAEncryption
*   Certificate level 2: Public key type RSA (4096/152 Bits/secBits), signed using sha256WithRSAEncryption
*   subjectAltName: "pocketid.server.de" matches cert's "pocketid.server.de"
* OpenSSL verify result: 0
* SSL certificate verified via OpenSSL.
* Established connection to pocketid.server.de (... port 443) from ... port 33744 
* using HTTP/2
* [HTTP/2] [1] OPENED stream for https://pocketid.server.de/
* [HTTP/2] [1] [:method: GET]
* [HTTP/2] [1] [:scheme: https]
* [HTTP/2] [1] [:authority: pocketid.server.de]
* [HTTP/2] [1] [:path: /]
* [HTTP/2] [1] [user-agent: curl/8.21.0]
* [HTTP/2] [1] [accept: */*]
> GET / HTTP/2
> Host: pocketid.server.de
> User-Agent: curl/8.21.0
> Accept: */*
> 
* Request completely sent off

But when I run this curl -6 -v https://pocketid.server.de command inside the container, I dont get the correct certificate

* Host pocketid.server.de:443 was resolved.
* IPv6: ....
* IPv4: (none)
*   Trying ....
* ALPN: curl offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* SSL Trust Anchors:
*   CAfile: /etc/ssl/certs/ca-certificates.crt
*   CApath: /etc/ssl/certs
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / x25519 / RSASSA-PSS
* ALPN: server accepted h2
* Server certificate:
*   subject: C=US; ST=CA; L=Carlsbad; O=Linuxserver.io; OU=LSIO Server; CN=*
*   start date: Oct 10 06:22:39 2025 GMT
*   expire date: Oct  8 06:22:39 2035 GMT
*   issuer: C=US; ST=CA; L=Carlsbad; O=Linuxserver.io; OU=LSIO Server; CN=*
*   Certificate level 0: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption
* SSL: certificate subject name '*' does not match target hostname 'pocketid.server.de'
* closing connection #0
curl: (60) SSL: certificate subject name '*' does not match target hostname 'pocketid.server.de'
More details here: https://curl.se/docs/sslcerts.html

curl failed to verify the legitimacy of the server and therefore could not
establish a secure connection to it. To learn more about this situation and
how to fix it, please visit the webpage mentioned above.

Problem only exists on Version > 26.05.1
v26.05.1 does not have this problem

Langage dominant
Dockerfile
Étoiles
1k
Forks
139
Métriques de merge des PR
Aucune PR mergée en 30 j

Guide de contribution

Ouvrir le guide de contribution

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Issues similaires

Plus d'issues Security

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.