Sitelet https://github.com/Netis/cloud-probe/issues/232
Skip to content

[cpdaemon] CPM HTTP client disables TLS verification unconditionally (InsecureSkipVerify) #232

Description

@vaderyang

Environment

  • CP version: v0.9.4 (commit f925e5f6)
  • OS: any
  • Platform: container / VM

Description

cpdaemon connects to the CPM with server certificate verification disabled, with no switch to turn it on:

  • cpdaemon/cmd/internal/asm/provider.go:114 → InsecureSkipVerify: true

Anyone able to man-in-the-middle the CPM channel can present any self-signed certificate and return forged JSON. Those responses drive task creation, BPF expressions, forward hosts and output targets on the probe - so this is a remotely influenceable channel, not a locally visible issue.

Steps to reproduce

  1. Run a fake CPM HTTPS server with a self-signed certificate.
  2. Point cpm.base_url at it.
  3. cpdaemon completes the handshake and accepts its responses (no certificate error).

Expected

Verify the server certificate by default (allow turning it off explicitly), and support mTLS. (Note: PKCS#12 client certs are only used in the provider.go:116 branch, which is orthogonal to server verification.)

Actual

Unconditional InsecureSkipVerify: true; there is no config to enable verification.

Notes

Found by source review while writing an independent Rust port; the threat model and a temporary mitigation (dedicated management network / local reverse proxy that validates the upstream certificate) are documented in that port's SECURITY.md.


中文原文

测试环境

  • CP 版本:v0.9.4(commit f925e5f6)
  • 操作系统:任意
  • 运行平台:容器 / 虚拟机

问题描述

cpdaemon 连接 CPM 时无条件关闭了 TLS 证书校验,且没有开关:

  • cpdaemon/cmd/internal/asm/provider.go:114 → InsecureSkipVerify: true

任何能对 CPM 通道做中间人的一方,都可以用任意自签证书冒充 CPM 并返回伪造的 JSON;而这些响应会驱动探针创建采集任务、下发 BPF 表达式 / 转发主机 / 输出目标。即:这是可远程影响探针行为的通道,而不是仅本地可见的问题。

重现方法

  1. 起一个"假 CPM" HTTPS 服务端(自签证书);
  2. 配置 cpm.base_url 指向它;
  3. 观察 cpdaemon 正常握手并接受其响应(无证书错误)。

期望

默认校验服务端证书(允许显式配置关闭),并支持 mTLS。(注:PKCS#12 客户端证书仅在配置了 cert 时于 provider.go:116 分支使用,与"是否校验服务端"是两件事。)

实际

无条件 InsecureSkipVerify: true,无法通过配置开启校验。

附件 / 说明

本条由独立 Rust 移植过程中的源码对照发现;威胁模型与临时缓解(专用管理网 / 本地反代校验上游证书)亦记录在移植仓库的 SECURITY.md。

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions