Can we get DEBUG loggin from the OpenSSL library?
メンテナーはふだん 1 日以内に返信
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 28/100
- issue の種類
- 機能追加
- 明瞭さ
- おおむね明確
- 活発さ
- 停滞
- 領域
- cryptography, security
調査の方向性
crypto/x509/t_x509.c で参照されている OpenSSL のデバッグ出力から始め、Ruby の OpenSSL::debug の動作と比較します。verify_callback と store_context の例を確認し、アプリケーションレベルのコールバックなしで同等の証明書詳細を提供できる、Ruby に公開されたフラグが存在するかどうかを判断します。提案するインターフェースと、そこで想定されるログ出力の動作が定義され、テストされていれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Hi,
Problem
As a developer I would like to see (DEBUG) logging from OpenSSL. We have a Ruby application that connects to Amazon Cloudfront to retrieve a file. This runs through a network outside of our control containing NAT gateways, proxies, etc.
This works 99% of the time, but Intermittently we get a self signed certificate error:
OpenSSL::SSL::SSLError (SSL_connect returned=1 errno=0
peeraddr=18.66.171.65:443 state=error: certificate verify failed
(self signed certificate in certificate chain))
But it doesn't show WHICH certificate (or subject, fignerprint, ...) is being seen.
Question / Request
Ideally we would have a ruby OpenSSL flag that instructs OpenSSL to do its (DEBUG) logging so we can get this information. I can see OpenSSL is logging the desired information in:
Is it possible to get the Ruby app to log this information?
I have found OpenSSL::debug=true, but this only seems to trigger debug logging done in this Ruby Gem.
In java we have -Djava.net.debug=ssl, but I realize that is not using OpenSSL underneath.
Alternative
I have found a way to get Ruby to log the self-signed certificate that is being seen in Ruby via https://github.com/mislav/ssl-tools/blob/master/doctor.rb. Something along these lines, where the store_context contains the failed certificat:
http.verify_callback = lambda { |verify_ok, store_context|
if !verify_ok
failed_cert = store_context.current_cert
failed_cert_reason = "%d: %s" % [ store_context.error, store_context.error_string ]
end
verify_ok
}
This is not ideal as it requires code changes in our Ruby apps, which is using httparty as a wrapper. Also we would be replicating logging that is already done by OpenSSL.
The fact that this SSL Docter script exists seems to confirm there is no Ruby OpenSSL::xxx flag to achieve this?
Would it be possible to implement such a flag? Is there an alternative way to achieve the same?
- 主要言語
- C
- スター
- 276
- フォーク
- 200
- 平均マージ
- 15時間 27分
- マージ済み PR(30日)
- 7
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
ruby/openssl のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
ruby/openssl#1116 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 55/100
ruby/openssl#1118 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
Expose XOFs like SHAKE128 and SHAKE256対応中かも @rhenium が 89 日前に担当しました。 オープン
難易度 4/5 3〜5日 初心者へのやさしさ 48/100
ruby/openssl#1082 · コメント 4 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
ruby/openssl#1075 · コメント 4 件 ·
メンテナーはふだん 1 日以内に返信
-
Unchecked *_set_* calls対応中かも @ndossche が 159 日前に担当しました。 オープン
難易度 4/5 3〜5日 初心者へのやさしさ 35/100
ruby/openssl#1038 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
libsdl-org/SDL#16444 ·
メンテナーはふだん 1 日以内に返信
-
bug Component component: net
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
RT-Thread/rt-thread#11852 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
MiSTer-devel/ao486_MiSTer#243 ·
-
Dropped last row with parallel scan of attached SQLite tables if the rowid range is a multiple of 122,880対応中かも @staticlibs が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
duckdb/duckdb-sqlite#240 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 66/100
siderolabs/pkgs#1710 ·
メンテナーはふだん 1 日以内に返信