Repository navigation
Malformed crt with HTTPS SNI causes hang - no error, no result #867
Description
Activity
Confirmed broken in
- v0.12.0 on OS X
- v1.2.0 on OS X
- v1.2.0 on ARM6
Confirmed working in
- v0.10.36 on OS X
- v0.10.36 on ARM6
Perhaps there's an API change that I'm unaware of? If so it seems like this should throw an error, not just hang.
- changed the title
[-]HTTPS SNI broken on arm6l (maybe others as well)[/-][+]Using HTTPS SNI causes hang - no error, no result[/+]on Feb 17, 2015 - changed the title
[-]Using HTTPS SNI causes hang - no error, no result[/-][+]Malformed crt with HTTPS SNI causes hang - no error, no result[/+]on Feb 17, 2015 Okay, so
v0.10.36has a flaw that allows it to work - it ignores the key file instead of erroring on it. A key file, obviously, should not get loaded into the CA chain.node.js / io.js latest have the flaw that although they don't work with a key file in the chain (good), they don't give an error or any indication of what went wrong.
After removing the key file that was in the wrong place:
├── vhost-sni-server.js ├── certs │ ├── ca │ │ ├── dummy-root-ca.crt.pem │ │ └── my-root-ca.crt.pem │ ├── README.md │ └── server │ ├── dummy-server.crt.pem │ ├── dummy-server.key.pem │ ├── my-server.crt.pem │ └── my-server.key.pemIt works.
# using the name on the cert curl https://local.helloworld3000.com:65443 --cacert certs/ca/dummy-root-ca.crt.pem > Cannot GET / # using insecure curl https://localhost:65443 -k > Cannot GET /I can upload the exact certs that I'm using upon request. They're all test / dummy certs anyway, so no risk there.
Hmm... my workaround didn't work on ARM, only on OS X. There's still something wrong...
It only happens when I return the crts immediately (not using the optional callback) AND there's a malformed crt (aka a key) in the chain.
If I use the callback or I take out the bad crt it works as expected (except I don't remember if using the callback sends an error or silently ignores the key).
And it happens on OS X, but on Raspberry Pi returning immediately doesn't work at all anyway.
I'd have to reinstall v1.2 or master to be certain, but I had a test case On v1.2 at the time I created the issue.
@coolaj86 returning context is not supported anymore, I'm not sure how it could be working :)
Maybe I had my node versions mixed up. Maybe I was actually on 0.11.
In that case, sorry for the noise, I'll close this and the related issue and reopen if I can reconfirm.
This just hangs without throwing an error or completing the request:
Expected result
client receives
server logs
Reduced Test Case
directory layout