Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

auth: call_client_cert_callback() discards passphrase for encrypted keys

Đang mở Phù hợp với người mới
#18,467 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
1/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
92/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
python
Lĩnh vực
authentication, security

Hướng nghiên cứu

Bắt đầu trong packages/google-auth/google/auth/transport/_mtls_helper.py tại call_client_cert_callback(), sau đó đọc test_call_client_cert_callback trong packages/google-auth/tests/transport/test__mtls_helper.py. Cập nhật đối số callback và kỳ vọng của test, rồi chạy test tập trung để xác minh rằng việc xoay vòng khóa được mã hóa không còn làm mất passphrase.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

call_client_cert_callback() in google.auth.transport._mtls_helper calls get_client_ssl_credentials(generate_encrypted_key=True) and discards the returned passphrase, returning only (cert_bytes, key_bytes).

When using SecureConnect (context_aware_metadata.json), generate_encrypted_key=True passes --with_passphrase to the certificate provider command, producing an encrypted PEM private key. During 401 certificate rotation, AuthorizedSession.request() and AuthorizedHttp.urlopen() pass those credentials to configure_mtls_channel() without the passphrase. SSLContext.load_cert_chain() then receives the encrypted key with password=None, causing OpenSSL to prompt for a passphrase on /dev/tty or fail with OSError and raise MutualTLSChannelError.

By contrast, initial mTLS setup in get_client_cert_and_key() passes generate_encrypted_key=False, relying on secure_cert_key_paths() to keep private keys in memory (os.memfd_create on Linux) or encrypt them on the fly with an ephemeral passphrase when falling back to temporary files.

Proposed Fix

Update call_client_cert_callback() in packages/google-auth/google/auth/transport/_mtls_helper.py to pass generate_encrypted_key=False:

def call_client_cert_callback():
    """Calls the client cert callback and returns the certificate and key."""
    _, cert_bytes, key_bytes, _ = get_client_ssl_credentials(
        generate_encrypted_key=False
    )
    return cert_bytes, key_bytes

Update test_call_client_cert_callback in packages/google-auth/tests/transport/test__mtls_helper.py to expect generate_encrypted_key=False.

Ngôn ngữ chính
Python
Star
5.4k
Fork
1.8k
Merge trung bình
2 ngày 3 giờ
Pull request đã merge (30 ngày)
109

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của googleapis/google-cloud-python

Tất cả issue của googleapis/google-cloud-python

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.