Conversation
This was referenced Sep 25, 2026
This was referenced Sep 25, 2026
david-yu
added this pull request to stack #12
September 25, 2026 16:16
The GnuTLS backend passes server_name to gnutls_certificate_verify_peers3, so a certificate that chains to a trusted CA but is issued for a different host (or a different IP SAN) fails verification. The OpenSSL backend only ever checked the chain: SSL_VERIFY_PEER with no expected host, so any trusted certificate was accepted for any server_name. Add tls_options::verify_server_name. On OpenSSL it registers the expected identity on the session's X509_VERIFY_PARAM — an IP literal (brackets and zone stripped) via X509_VERIFY_PARAM_set1_ip_asc, a DNS name via SSL_set1_host without partial wildcards — so the mismatch surfaces through SSL_get_verify_result and the existing verify() path. It defaults to false: clients that connect by address to servers whose certificates carry no IP SAN keep working until they opt in. GnuTLS keeps its always-on check; the header documents the difference. The test certificate gains an IP SAN for ::1 next to 127.0.0.1, and test_alt_names asserts both values. New cases run the echo test with the flag set: matching DNS name and IP literals (127.0.0.1, ::1, [::1]) pass, a wrong DNS name and wrong addresses raise verification_error.
david-yu
force-pushed
the
ipv6/07-tls-verify-server-name
branch
from
September 25, 2026 18:11
470cf68 to
96fad94
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part 7 of 10 of the IPv6 series, split out of #1 and rebased on current
scylladb/seastarmaster. Based on #7, so the diff here is only this PR's commit.Why
GnuTLS checks the peer certificate against
server_name. OpenSSL only checks the chain (SSL_VERIFY_PEERwith no expected host), so it accepts any trusted certificate for any name. The two backends disagree, and once callers pass IP literals asserver_name(previous PR) there is no way to have OpenSSL check an IP SAN.What
96fad948b) —tls_options::verify_server_name, defaultfalse. On OpenSSL it sets the expected host or IP on the session'sX509_VERIFY_PARAM, so a mismatch surfaces through the existingverify()path. GnuTLS keeps its always-on check; the header documents the difference. The test certificate gains anIP:::1SAN.The question for review
Should OpenSSL instead match GnuTLS and verify whenever
server_nameis set? That would break clients that connect by address to certificates without an IP SAN, so this keeps it opt-in.Testing
Matching DNS names and IP literals (
127.0.0.1,::1,[::1]) pass; a wrong name or address raisesverification_error. With the new check removed,test_verify_server_name_dns_mismatchreports "Should have gotten validation error", i.e. OpenSSL accepts any trusted certificate for any name today.On the core-aws VM (Ubuntu 24.04, GCC 14, C++23, RelWithDebInfo, GnuTLS and OpenSSL in one tree), this PR's head builds and passes
dns,ipv6,socket,rpc,httpd,httpd_openssl,tls,tls_openssl,network_interface,websocketandunix_domainwithSEASTAR_TEST_REQUIRE_IPV6=1, so none of their IPv6 cases skipped.Stack