Repository navigation
https SNICallback hangs if optional callback isn't provided on ARM6 (and possibly others) #869
Description
Activity
(testing from my macbook to my rpi)
It hangs with
curl https://10.0.0.20:65443by itself.It doesn't hang with
curl -k https://10.0.0.20:65443It does hang in Chrome with https://10.0.0.20:65443
Testing on localhost
Testing from the Raspberry Pi (localhost -> localhost):
Works or Gives Error
curl https://127.0.0.1:65443 -k curl https://10.0.0.20:65443 -k works curl https://127.0.0.1:65443 --cacert certs/ca/dummy-root-ca.crt curl https://10.0.0.20:65443 --cacert certs/ca/dummy-root-ca.crt curl: (51) SSL: certificate subject name 'local.helloworld3000.com' does not match target host name '10.0.0.20' curl https://127.0.0.1:65443 curl https://10.0.0.20:65443 curl: (60) SSL certificate problem: self signed certificate in certificate chain More details here: http://curl.haxx.se/docs/sslcerts.html curl performs SSL certificate verification by default, using a "bundle" of Certificate Authority (CA) public keys (CA certs). If the default bundle file isn't adequate, you can specify an alternate file using the --cacert option. If this HTTPS server uses a certificate signed by a CA represented in the bundle, the certificate verification probably failed due to a problem with the certificate (it might be expired, or the name might not match the domain name in the URL). If you'd like to turn off curl's verification of the certificate, use the -k (or --insecure) option.Hangs Forever
curl https://localhost:65443 curl https://localhost:65443 --cacert certs/ca/dummy-root-ca.crt.pem curl https://localhost:65443 -k curl https://local.helloworld3000.com:65443 curl https://local.helloworld3000.com:65443 --cacert certs/ca/dummy-root-ca.crt.pem curl https://local.helloworld3000.com:65443 -kTesting NOT on localhost
curl -vvv https://10.0.0.20:65443 * Rebuilt URL to: https://10.0.0.20:65443/ * Hostname was NOT found in DNS cache * Trying 10.0.0.20... * Connected to 10.0.0.20 (10.0.0.20) port 65443 (#0) * WARNING: using IP address, SNI is being disabled by the OS. (hangs forever)curl -vvv -k https://10.0.0.20:65443 * Rebuilt URL to: https://10.0.0.20:65443/ * Hostname was NOT found in DNS cache * Trying 10.0.0.20... * Connected to 10.0.0.20 (10.0.0.20) port 65443 (#0) * TLS 1.2 connection using TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 * Server certificate: local.helloworld3000.com * Server certificate: example.com > GET / HTTP/1.1 > User-Agent: curl/7.37.1 > Host: 10.0.0.20:65443 > Accept: */* > < HTTP/1.1 200 OK < Date: Tue, 17 Feb 2015 20:00:03 GMT < Connection: keep-alive < Transfer-Encoding: chunked < * Connection #0 to host 10.0.0.20 left intact workscurl -vvv https://10.0.0.20:65443 --cacert certs/ca/dummy-root-ca.crt.pem * Rebuilt URL to: https://10.0.0.20:65443/ * Hostname was NOT found in DNS cache * Trying 10.0.0.20... * Connected to 10.0.0.20 (10.0.0.20) port 65443 (#0) * WARNING: using IP address, SNI is being disabled by the OS. (hangs forever)- changed the title
[-]https SNICallback always hangs on ARM6 (Raspberry Pi)[/-][+]https SNICallback always hangs on ARM6 (and possibly others)[/+]on Feb 17, 2015 The Problem and the Workaround
The API for SNICallback has changed since
v0.10.36. Now there's an optional callback, but on ARM, for some reason, returning the context without using the callback doesn't work, while on OS X it does work.P.S. I'm definitely in favor of the callback remaining optional since it's difficult for me, the node user, to feature detect which version of node / io.js my code is running on.
Update: Nevermind, I can check
'function' === typeof cb... DUHUpdate 2: it turns out I need the async version anyway because I'll be using let's encrypt and I have to do some lazy loading for performance reasons.
- changed the title
[-]https SNICallback always hangs on ARM6 (and possibly others)[/-][+]https SNICallback hangs if optional callback isn't provided on ARM6 (and possibly others)[/+]on Feb 17, 2015 See my comment here: nodejs/node-v0.x-archive#9236 (comment)
This is a DIFFERENT bug. (and #867 is yet another different bug)
The problem here is that on OS X the callback is optional (if you return synchronously, it works) but on ARM returning synchronously is not supported and you MUST use the callback.
You must use the callback on every platform. I don't think that there is any way to opt-out from it, unless the
SNICallbackis not called for that connection.Oh, I didn't see this comment here before.
I'll close the issue, but I'm interested to retest since I originally claimed to have tested it on 2 devices with 1.2 and 1 with 0.12...
Originally I found this bug #867 on ARM6 and while testing further on OS X I found a workaround.
I took my band-aided test case back to my Rapsberry Pi to test and found that the https request still just hangs forever.
I commented out the
SNICallbackentirely and found that the certificates I'm loading are working by themselves, but the SNICallback is broken.To experience the hang, simply uncomment the
SNICallbackblock.