[
https://issues.apache.org/jira/browse/KNOX-3498?focusedWorklogId=1045059&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1045059
]
ASF GitHub Bot logged work on KNOX-3498:
----------------------------------------
Author: ASF GitHub Bot
Created on: 01/Oct/26 07:35
Start Date: 01/Oct/26 07:35
Worklog Time Spent: 10m
Work Description: smolnar82 commented on code in PR #1437:
URL: https://github.com/apache/knox/pull/1437#discussion_r4152931330
##########
gateway-server/src/main/java/org/apache/knox/gateway/services/token/impl/DefaultTokenAuthorityService.java:
##########
@@ -312,11 +320,60 @@ public boolean verifyToken(JWT token, String jwksUrl,
String algorithm, JOSEObje
verified = true;
}
} catch (BadJOSEException | JOSEException | ParseException |
MalformedURLException e) {
+ if (isIpLiteralTlsFailure(jwksUrl, e)) {
+ /* BC-FIPS refuses HTTPS endpoint identification against a bare IP */
+ if (FipsUtils.isFipsEnabledWithBCProvider()) {
+ LOG.jwksIpLiteralHostUnderFips(jwksUrl);
+ } else {
+ LOG.jwksIpLiteralHost(jwksUrl);
+ }
+ }
throw new TokenServiceException("Cannot verify token.", e);
}
return verified;
}
+ /**
+ * Whether a JWKS failure is a TLS/trust failure against an IP literal host,
the one case where
+ * {@code certificate_unknown(46)} says nothing at all about the contents of
the truststore.
+ *
+ * @param jwksUrl the JWKS endpoint that was being fetched, possibly {@code
null}
+ * @param failure the failure to inspect
+ * @return {@code true} when the host is an IP literal and the chain carries
a TLS/trust failure
+ */
+ static boolean isIpLiteralTlsFailure(final String jwksUrl, final Throwable
failure) {
+ if (jwksUrl == null) {
+ return false;
+ }
+ final String host;
+ try {
+ host = URI.create(jwksUrl).getHost();
+ } catch (IllegalArgumentException e) {
+ /* not a URI we can reason about; we have nothing useful to add */
+ return false;
+ }
+ if (host == null) {
+ return false;
+ }
+ /* getHost() hands an IPv6 literal with brackets. Sanitize it */
+ final String bare = host.length() > 1 && host.charAt(0) == '['
+ ? host.substring(1, host.length() - 1) : host;
+
+ return InetAddresses.isInetAddress(bare) && isTlsTrustFailure(failure);
Review Comment:
I contributed this change here, I hope you don't mind.
Issue Time Tracking
-------------------
Worklog Id: (was: 1045059)
Time Spent: 40m (was: 0.5h)
> OIDC issuer discovery url with IP breaks when FIPS enabled.
> -----------------------------------------------------------
>
> Key: KNOX-3498
> URL: https://issues.apache.org/jira/browse/KNOX-3498
> Project: Apache Knox
> Issue Type: Bug
> Components: Server
> Reporter: Sandeep More
> Assignee: Sandeep More
> Priority: Major
> Time Spent: 40m
> Remaining Estimate: 0h
>
> A trusted OIDC issuer whose discovery url has IP (used in`jwks_uri`) breaks
> with BouncyCastle FIPS, the failure looks like a missing CA which is
> misleading.
>
> For KnoxIDF, registering a trusted OIDC issuer whose discovery document
> advertises `jwks_uri` as an IP makes token exchange fail, and the reported
> error is looks similar to trust-store misconfiguration. Example is in k8s
> : kube-apiserver advertises an IP by default, e.g.
> "jwks_uri": "https://10.83.4.208:6443/openid/v1/jwks"
>
> *Workaround:*
> 1. Knox config:
> Move the issuer onto the static verification route, which accepts an explicit
> JWKS URL list, and give it the hostname form of the endpoint:
> <param><name>jwt.expected.issuer</name>
>
> <value>KNOXSSO,https://kubernetes.default.svc.cluster.local</value></param>
> <param><name>knox.token.jwks.urls</name>
>
> <value>https://knox.example.com/gateway/knox-token/knoxtoken/api/v1/jwks.json,
>
> https://kubernetes.default.svc.cluster.local/openid/v1/jwks</value></param>
> 2. K8S Config
> Alternatively fix it at the source with kube-apiserver
> `--service-account-jwks-uri=https://kubernetes.default.svc.cluster.local/openid/v1/jwks`.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)