Configuration issues identified by SSL Labs
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 35/100
Hướng nghiên cứu
Bắt đầu với module openssl của Racket và cấu hình HTTPS mặc định của web server, sau đó so sánh ưu tiên cipher suite và hành vi DHE của nó với cấu hình Apache của Certbot được liên kết trong issue. Sử dụng SSL Labs' SSL Server Test để xác minh rằng các giá trị mặc định ưu tiên các suite có forward secrecy và hỗ trợ các phương thức trao đổi khóa dự kiến.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
The SSL Labs "SSL Server Test" service (https://www.ssllabs.com/ssltest/) identifies some aspects of the Racket web server's default HTTPS configuration that should be improved. Most significantly, it says, "This server does not support Forward Secrecy with the reference browsers. Grade capped to B."
I am still looking into the situation in more detail, but I've noticed at least two differences from the configuration generated by Certbot for Apache, which SSL Labs approves of:
- While the Racket web server supports ECDHE, it doesn't seem to prefer more secure cypher suites to less secure ones.
- The Racket web server's default configuration doesn't seem to enable DHE. It seems like this would force clients that support DHE but not ECDHE to fall back to RSA key exchange without forward secrecy.
I'm happy to do some implementation work here, but I haven't worked with these low-level portions before. In particular, I haven't figured out how to designate preferred cypher suites with the Racket openssl module.
- Ngôn ngữ chính
- Racket
- Star
- 100
- Fork
- 48
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của racket/web-server
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 70/100
racket/web-server#46 ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 38/100
racket/web-server#141 ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
racket/web-server#140 ·
-
`make-dir-store` is not atomicĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 45/100
racket/web-server#135 ·
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
racket/web-server#131 · 1 bình luận ·
Tất cả issue của racket/web-server
Issue tương tự
-
Maven path-index: "Ambiguous or noncanonical artifact path" error does not report the offending pathĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
pulp/pulp_maven#524 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 76/100
ethereum/execution-apis#935 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
rc_runtime_activate_richpresence leaves a half-initialised entry when the buffer allocation failsĐang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
RetroAchievements/rcheevos#558 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Qiskit/qiskit-ibm-runtime#3461 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
module: unknown type: bug/reported
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 78/100
OpenXiangShan/XiangShan#6688 ·
Maintainer thường phản hồi trong vòng 1 ngày