Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

[BUG] OIDC // IPv6 // certificate subject name '*' does not match target hostname

未關閉
#296 3 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

評估

難度
4/5
預估耗時
3-5 天
新手友好度
45/100
Issue 類型
缺陷
描述清晰度
需要釐清
活躍度
活躍
技術堆疊
docker

研究方向

未指定檔案或測試。首先,在 v26.05.1 及更新版本中重現對 /.well-known/openid-configuration 的 OIDC discovery 請求,比較 curl -4 和 curl -6 的行為以及傳回的憑證。IPv6 能夠連線到正確的憑證,且 OIDC 登入成功而不發生主機名稱不相符,即表示完成。

由索引模型根據 Issue 內容生成。

描述

Is there an existing issue for this?
  • I have searched the existing issues
Current Behavior

When I try to log in with my OIDC provider, I get the following error message:

 OIDC Discovery Error: HTTP request failed during discovery with error: cURL error 60: SSL: certificate subject name '*' does not match target hostname 'pocketid.server.de' (see https://curl.se/libcurl/c/libcurl-errors.html) for https://pocketid.server.de/.well-known/openid-configuration

It seems to have something to do with IPv6.

When I run this curl -4 -v https://pocketid.server.de command inside the container, I get the correct certificate

* Host pocketid.server.de:443 was resolved.
* IPv6: (none)
* IPv4: ...
*   Trying ...:443...
* ALPN: curl offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* SSL Trust Anchors:
*   CAfile: /etc/ssl/certs/ca-certificates.crt
*   CApath: /etc/ssl/certs
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_128_GCM_SHA256 / X25519MLKEM768 / id-ecPublicKey
* ALPN: server accepted h2
* Server certificate:
*   subject: CN=pocketid.server.de
*   start date: May 28 10:38:49 2026 GMT
*   expire date: Aug 26 10:38:48 2026 GMT
*   issuer: C=US; O=Let's Encrypt; CN=E7
*   Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA384
*   Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using sha256WithRSAEncryption
*   Certificate level 2: Public key type RSA (4096/152 Bits/secBits), signed using sha256WithRSAEncryption
*   subjectAltName: "pocketid.server.de" matches cert's "pocketid.server.de"
* OpenSSL verify result: 0
* SSL certificate verified via OpenSSL.
* Established connection to pocketid.server.de (... port 443) from ... port 33744 
* using HTTP/2
* [HTTP/2] [1] OPENED stream for https://pocketid.server.de/
* [HTTP/2] [1] [:method: GET]
* [HTTP/2] [1] [:scheme: https]
* [HTTP/2] [1] [:authority: pocketid.server.de]
* [HTTP/2] [1] [:path: /]
* [HTTP/2] [1] [user-agent: curl/8.21.0]
* [HTTP/2] [1] [accept: */*]
> GET / HTTP/2
> Host: pocketid.server.de
> User-Agent: curl/8.21.0
> Accept: */*
> 
* Request completely sent off

But when I run this curl -6 -v https://pocketid.server.de command inside the container, I dont get the correct certificate

* Host pocketid.server.de:443 was resolved.
* IPv6: ....
* IPv4: (none)
*   Trying ....
* ALPN: curl offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* SSL Trust Anchors:
*   CAfile: /etc/ssl/certs/ca-certificates.crt
*   CApath: /etc/ssl/certs
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / x25519 / RSASSA-PSS
* ALPN: server accepted h2
* Server certificate:
*   subject: C=US; ST=CA; L=Carlsbad; O=Linuxserver.io; OU=LSIO Server; CN=*
*   start date: Oct 10 06:22:39 2025 GMT
*   expire date: Oct  8 06:22:39 2035 GMT
*   issuer: C=US; ST=CA; L=Carlsbad; O=Linuxserver.io; OU=LSIO Server; CN=*
*   Certificate level 0: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption
* SSL: certificate subject name '*' does not match target hostname 'pocketid.server.de'
* closing connection #0
curl: (60) SSL: certificate subject name '*' does not match target hostname 'pocketid.server.de'
More details here: https://curl.se/docs/sslcerts.html

curl failed to verify the legitimacy of the server and therefore could not
establish a secure connection to it. To learn more about this situation and
how to fix it, please visit the webpage mentioned above.

Problem only exists on Version > 26.05.1
v26.05.1 does not have this problem

主要語言
Dockerfile
星號
1k
分支
139
PR 合併指標
30 天內沒有已合併 PR

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

相似的 Issue

更多 Security Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。