Skip to content

tls: do not send IP literals in the SNI extension - #7

Open
david-yu wants to merge 1 commit into
ipv6/05-zones-literalsfrom
ipv6/06-tls-sni
Open

david-yu wants to merge 1 commit into
ipv6/05-zones-literalsfrom
ipv6/06-tls-sni

Conversation

@david-yu

@david-yu david-yu commented Sep 25, 2026 •

Copy link
Copy Markdown
Owner

Part 6 of 10 of the IPv6 series, split out of #1 and rebased on current scylladb/seastar master. Based on #6, so the diff here is only this PR's commit.

Why

Callers that connect by address pass the address as tls_options::server_name. Both backends copied it into the SNI extension, which RFC 6066 §3 forbids for IP literals, and servers that validate the extension reject the ClientHello.

What

  • tls: do not send IP literals in the SNI extension (bfaba39af) — both backends skip the extension for a literal, bracketed or not. Verification is unchanged: the literal is still matched against the certificate's IP SANs. The GnuTLS call's return value is now checked.

Testing

A plain socket reads the ClientHello the client sends: DNS names carry the extension, IPv4 and IPv6 literals do not.

On the core-aws VM (Ubuntu 24.04, GCC 14, C++23, RelWithDebInfo, GnuTLS and OpenSSL in one tree), this PR's head builds and passes dns, ipv6, socket, rpc, httpd, httpd_openssl, tls, tls_openssl, network_interface, websocket and unix_domain with SEASTAR_TEST_REQUIRE_IPV6=1, so none of their IPv6 cases skipped.

Stack

  1. tests, ci: fail instead of skip when IPv6 is expected #2 tests, ci: fail instead of skip when IPv6 is expected
  2. dns: reach nameservers over IPv6 #3 dns: reach nameservers over IPv6
  3. dns: literals for any family, c-ares error text, link-local nameservers #4 dns: literals for any family, c-ares error text, link-local nameservers
  4. net, http, rpc: dual-stack listeners (IPV6_V6ONLY, IPv4-mapped peers) #5 net, http, rpc: dual-stack listeners (IPV6_V6ONLY, IPv4-mapped peers)
  5. net: IPv6 zones and strict literal parsing #6 net: IPv6 zones and strict literal parsing
  6. tls: do not send IP literals in the SNI extension #7 tls: do not send IP literals in the SNI extension ← this PR
  7. tls: verify server_name on OpenSSL, opt-in #8 tls: verify server_name on OpenSSL, opt-in
  8. net: ipv6_addr equality and hash, ipv4_addr(socket_address) throws instead of terminating #9 net: ipv6_addr equality and hash, ipv4_addr(socket_address) throws instead of terminating
  9. net: listen on an unspecified address binds any family #10 net: listen on an unspecified address binds any family
  10. http: build the Host header from an address in authority form #11 http: build the Host header from an address in authority form

tls_options::server_name is the name verification checks the certificate
against, and callers that connect by address pass the address. Both
backends copied it verbatim into the server_name extension, which RFC 6066
§3 forbids for IPv4 and IPv6 literals; servers that validate the extension
reject the ClientHello.

Skip the extension for a literal (bracketed or not) in both the OpenSSL
and the GnuTLS backend. Verification is unchanged: the literal is still
matched against the certificate's IP SANs. The GnuTLS call's return value
is now checked instead of dropped.

Tested by a plain socket that reads the ClientHello a client sends and
looks for the extension: DNS names appear, IPv4/IPv6 literals do not.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant