auth: call_client_cert_callback() discards passphrase for encrypted keys
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 1/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 92/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- python
调研方向
从 packages/google-auth/google/auth/transport/_mtls_helper.py 中的 call_client_cert_callback() 开始,然后阅读 packages/google-auth/tests/transport/test__mtls_helper.py 中的 test_call_client_cert_callback。更新 callback 参数和测试预期,然后运行针对性测试,以验证加密密钥轮换不再丢失 passphrase。
由索引模型根据 Issue 内容生成。
描述
call_client_cert_callback() in google.auth.transport._mtls_helper calls get_client_ssl_credentials(generate_encrypted_key=True) and discards the returned passphrase, returning only (cert_bytes, key_bytes).
When using SecureConnect (context_aware_metadata.json), generate_encrypted_key=True passes --with_passphrase to the certificate provider command, producing an encrypted PEM private key. During 401 certificate rotation, AuthorizedSession.request() and AuthorizedHttp.urlopen() pass those credentials to configure_mtls_channel() without the passphrase. SSLContext.load_cert_chain() then receives the encrypted key with password=None, causing OpenSSL to prompt for a passphrase on /dev/tty or fail with OSError and raise MutualTLSChannelError.
By contrast, initial mTLS setup in get_client_cert_and_key() passes generate_encrypted_key=False, relying on secure_cert_key_paths() to keep private keys in memory (os.memfd_create on Linux) or encrypt them on the fly with an ephemeral passphrase when falling back to temporary files.
Proposed Fix
Update call_client_cert_callback() in packages/google-auth/google/auth/transport/_mtls_helper.py to pass generate_encrypted_key=False:
def call_client_cert_callback():
"""Calls the client cert callback and returns the certificate and key."""
_, cert_bytes, key_bytes, _ = get_client_ssl_credentials(
generate_encrypted_key=False
)
return cert_bytes, key_bytes
Update test_call_client_cert_callback in packages/google-auth/tests/transport/test__mtls_helper.py to expect generate_encrypted_key=False.
- 主要语言
- Python
- 星标
- 5.4k
- 派生
- 1.8k
- 平均合并
- 2 天 3 小时
- 30 天内合并 PR
- 109
环境准备
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
googleapis/google-cloud-python 的其他 Issue
-
auth priority: p2 type: bug
难度 2/5 1-3 小时 新手友好度 88/100
googleapis/google-cloud-python#18428 ·
维护者通常 1 天内回复
-
priority: p2 type: bug
难度 2/5 1-3 小时 新手友好度 72/100
googleapis/google-cloud-python#18375 · 1 条评论 ·
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 76/100
googleapis/google-cloud-python#18339 ·
维护者通常 1 天内回复
-
auth priority: p2
难度 2/5 1-3 小时 新手友好度 88/100
googleapis/google-cloud-python#18315 ·
维护者通常 1 天内回复
-
priority: p2 type: bug
难度 2/5 1-3 小时 新手友好度 78/100
googleapis/google-cloud-python#18260 ·
维护者通常 1 天内回复
查看 googleapis/google-cloud-python 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 86/100
维护者通常 1 天内回复
-
难度 2/5 1-2 天 新手友好度 70/100
-
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 7 天内回复
-
难度 2/5 1-3 小时 新手友好度 70/100
lmstudio-ai/mlx-engine#376 ·
-
难度 2/5 1-3 小时 新手友好度 72/100
pyiron/bagofholding#166 ·