Conversation
This was referenced Sep 25, 2026
This was referenced Sep 25, 2026
david-yu
added this pull request to stack #12
September 25, 2026 16:16
tls_options::server_name is the name verification checks the certificate against, and callers that connect by address pass the address. Both backends copied it verbatim into the server_name extension, which RFC 6066 §3 forbids for IPv4 and IPv6 literals; servers that validate the extension reject the ClientHello. Skip the extension for a literal (bracketed or not) in both the OpenSSL and the GnuTLS backend. Verification is unchanged: the literal is still matched against the certificate's IP SANs. The GnuTLS call's return value is now checked instead of dropped. Tested by a plain socket that reads the ClientHello a client sends and looks for the extension: DNS names appear, IPv4/IPv6 literals do not.
david-yu
force-pushed
the
ipv6/06-tls-sni
branch
from
September 25, 2026 18:11
7fc0764 to
bfaba39
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part 6 of 10 of the IPv6 series, split out of #1 and rebased on current
scylladb/seastarmaster. Based on #6, so the diff here is only this PR's commit.Why
Callers that connect by address pass the address as
tls_options::server_name. Both backends copied it into the SNI extension, which RFC 6066 §3 forbids for IP literals, and servers that validate the extension reject the ClientHello.What
bfaba39af) — both backends skip the extension for a literal, bracketed or not. Verification is unchanged: the literal is still matched against the certificate's IP SANs. The GnuTLS call's return value is now checked.Testing
A plain socket reads the ClientHello the client sends: DNS names carry the extension, IPv4 and IPv6 literals do not.
On the core-aws VM (Ubuntu 24.04, GCC 14, C++23, RelWithDebInfo, GnuTLS and OpenSSL in one tree), this PR's head builds and passes
dns,ipv6,socket,rpc,httpd,httpd_openssl,tls,tls_openssl,network_interface,websocketandunix_domainwithSEASTAR_TEST_REQUIRE_IPV6=1, so none of their IPv6 cases skipped.Stack