kpumuk opened a new pull request, #3652:
URL: https://github.com/apache/thrift/pull/3652

   <!-- Explain the changes in the pull request below: -->
   
   `Thrift::SSLSocket` reconfigured a caller-supplied 
`OpenSSL::SSL::SSLContext` in place to apply its separate peer-verification 
setting. This changed the caller’s verification mode and could install a 
certificate store on an object the application expected to configure and reuse 
itself. Ruby OpenSSL also freezes a context after it is used by a socket, 
making later attempts to apply a different setting fail.
   
   This change gives the context a single owner. When no context is supplied, 
Thrift creates one with peer verification enabled and the system certificate 
store. When an application supplies a context, Thrift passes it to OpenSSL 
without reconfiguring it; the context’s `verify_mode` and trust sources control 
certificate-chain verification. Thrift continues to check the server 
certificate against `server_hostname`, preserving hostname-mismatch detection.
   
   The Ruby README now documents both ownership modes and shows how to supply a 
context configured with `OpenSSL::SSL::VERIFY_NONE` when certificate-chain 
verification is intentionally disabled.
   
   <!-- We recommend you review the checklist/tips before submitting a pull 
request. -->
   
   - [x] Did you create an [Apache 
Jira](https://issues.apache.org/jira/projects/THRIFT/issues/) ticket? 
[THRIFT-6098](https://issues.apache.org/jira/browse/THRIFT-6098)
   - [x] If a ticket exists: Does your pull request title follow the pattern 
"THRIFT-NNNN: describe my issue"?
   - [x] Did you squash your changes to a single commit?  (not required, but 
preferred)
   - [x] Did you do your best to avoid breaking changes?  If one was needed, 
did you label the Jira ticket with "Breaking-Change"?
   - [x] If your change does not involve any code, include `[skip ci]` anywhere 
in the commit message to free up build resources.
   
   <!--
     The Contributing Guide at:
     https://github.com/apache/thrift/blob/master/CONTRIBUTING.md
     has more details and tips for committing properly.
   -->
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to