[
https://issues.apache.org/jira/browse/THRIFT-6098?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dmytro Shteflyuk resolved THRIFT-6098.
--------------------------------------
Fix Version/s: 0.25.0
Resolution: Fixed
> Ruby SSLSocket should verify peers by default
> ---------------------------------------------
>
> Key: THRIFT-6098
> URL: https://issues.apache.org/jira/browse/THRIFT-6098
> Project: Thrift
> Issue Type: Bug
> Components: Ruby - Library
> Affects Versions: 0.24.0
> Reporter: Dmytro Shteflyuk
> Assignee: Dmytro Shteflyuk
> Priority: Major
> Fix For: 0.25.0
>
> Time Spent: 20m
> Remaining Estimate: 0h
>
> h2. Background
> {{Thrift::SSLSocket}} currently passes its optional
> {{OpenSSL::SSL::SSLContext}} to OpenSSL without establishing consistent
> client-side peer-verification defaults. Consequently, the resulting behavior
> depends on whether and how the caller configured the supplied context.
> This differs from {{Thrift::HTTPClientTransport}}, which already enables peer
> verification by default.
> h2. Proposed behavior
> For the Ruby library in 0.25.0, {{Thrift::SSLSocket}} should:
> * verify the peer certificate by default;
> * apply the same default when no SSL context is supplied or when the caller
> supplies a blank {{OpenSSL::SSL::SSLContext}};
> * preserve a caller-provided CA file, CA directory, or certificate store;
> * use the system certificate store when the context has no configured trust
> source;
> * continue checking the certificate identity against {{server_hostname}}, or
> the connection host when no separate server hostname is supplied; and
> * provide an explicit {{verify_peer: false}} option for applications that
> intentionally disable peer identity checks.
> h2. Compatibility
> This is an intentional behavior change for the Ruby library in 0.25.0.
> Applications that intentionally connect without peer identity checks must
> update their {{Thrift::SSLSocket}} construction to pass {{verify_peer:
> false}} explicitly.
> Applications that provide their own CA file, CA directory, or certificate
> store should continue using those configured trust sources without
> modification.
> h2. Scope
> This change is limited to the Ruby {{Thrift::SSLSocket}} transport.
> {{Thrift::HTTPClientTransport}} already verifies HTTPS peers by default and
> does not require a behavior change. {{Thrift::RackApplication}} is also
> outside the scope because TLS negotiation is handled by the Rack server or
> reverse proxy before the Rack application receives a request.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)