auth: call_client_cert_callback() discards passphrase for encrypted keys
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 1/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 92/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- python
- Lĩnh vực
- authentication, security
Hướng nghiên cứu
Bắt đầu trong packages/google-auth/google/auth/transport/_mtls_helper.py tại call_client_cert_callback(), sau đó đọc test_call_client_cert_callback trong packages/google-auth/tests/transport/test__mtls_helper.py. Cập nhật đối số callback và kỳ vọng của test, rồi chạy test tập trung để xác minh rằng việc xoay vòng khóa được mã hóa không còn làm mất passphrase.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
call_client_cert_callback() in google.auth.transport._mtls_helper calls get_client_ssl_credentials(generate_encrypted_key=True) and discards the returned passphrase, returning only (cert_bytes, key_bytes).
When using SecureConnect (context_aware_metadata.json), generate_encrypted_key=True passes --with_passphrase to the certificate provider command, producing an encrypted PEM private key. During 401 certificate rotation, AuthorizedSession.request() and AuthorizedHttp.urlopen() pass those credentials to configure_mtls_channel() without the passphrase. SSLContext.load_cert_chain() then receives the encrypted key with password=None, causing OpenSSL to prompt for a passphrase on /dev/tty or fail with OSError and raise MutualTLSChannelError.
By contrast, initial mTLS setup in get_client_cert_and_key() passes generate_encrypted_key=False, relying on secure_cert_key_paths() to keep private keys in memory (os.memfd_create on Linux) or encrypt them on the fly with an ephemeral passphrase when falling back to temporary files.
Proposed Fix
Update call_client_cert_callback() in packages/google-auth/google/auth/transport/_mtls_helper.py to pass generate_encrypted_key=False:
def call_client_cert_callback():
"""Calls the client cert callback and returns the certificate and key."""
_, cert_bytes, key_bytes, _ = get_client_ssl_credentials(
generate_encrypted_key=False
)
return cert_bytes, key_bytes
Update test_call_client_cert_callback in packages/google-auth/tests/transport/test__mtls_helper.py to expect generate_encrypted_key=False.
- Ngôn ngữ chính
- Python
- Star
- 5.4k
- Fork
- 1.8k
- Merge trung bình
- 2 ngày 3 giờ
- Pull request đã merge (30 ngày)
- 109
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của googleapis/google-cloud-python
-
auth priority: p2 type: bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
googleapis/google-cloud-python#18428 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
priority: p2 type: bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
googleapis/google-cloud-python#18375 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 76/100
googleapis/google-cloud-python#18339 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
auth priority: p2
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
googleapis/google-cloud-python#18315 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
priority: p2 type: bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
googleapis/google-cloud-python#18260 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của googleapis/google-cloud-python
Issue tương tự
-
bug status/needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
prowler-cloud/prowler#12887 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area: desktop platform: macos priority: p3 status: ready type: enhancement
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
use-agent-os/agent-os#3484 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
open-telemetry/opentelemetry-python-contrib#5113 · 2 bình luận · 2 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
external
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
langchain-ai/docs#6255 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày