Sitelet https://web.archive.org/web/20201029071321/https://github.com/elastic/elasticsearch/issues/63784
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add KeyUsage, ExtendedKeyUsage, CipherSuite & Protocol to SSL diagnostics #63784

Open
tvernum opened this issue Oct 16, 2020 · 3 comments
Open

Add KeyUsage, ExtendedKeyUsage, CipherSuite & Protocol to SSL diagnostics #63784

tvernum opened this issue Oct 16, 2020 · 3 comments

Comments

@tvernum
Copy link
Contributor

@tvernum tvernum commented Oct 16, 2020

Per https://discuss.elastic.co/t/ldaps-and-chain-of-certificates/250724 it's possible to get an SSL failure & diagnostic when the cipher requires certain key usage that is not permitted by the certificate.

To assist in such diagnostics, it would be of assistance to print out the ceritficate's KeyUsage and the session's Cipher suite in the message.
While we're doing that, the cert's ExtendedKeyUsage and session Protocol are probably worth including as well.

@elasticmachine
Copy link
Collaborator

@elasticmachine elasticmachine commented Oct 16, 2020

Pinging @elastic/es-security (:Security/Network)

@AGZain
Copy link

@AGZain AGZain commented Oct 16, 2020

I'd like to start contributing to this issue.
Any hints on which part of the code I should start with, for this issue?

@Moe82
Copy link

@Moe82 Moe82 commented Oct 28, 2020 •

Hi, @tvernum . I'd like to work on this issue. Can you please provide a general format for how you want the 4 new strings to appear?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
4 participants
You can’t perform that action at this time.