Repository navigation
Intermediate certs don't work with SNICallback #2772
Copy link
Copy link
Closed
Labels
tlsIssues and PRs related to the tls subsystem.Issues and PRs related to the tls subsystem.
Description
Activity
- addedtlsIssues and PRs related to the tls subsystem.Issues and PRs related to the tls subsystem.
on Sep 9, 2015 +1 - I've just hit the same issue.
/cc @nodejs/crypto
Would concatenating those intermediate certificates alongside your
certinstead ofcaworks in this case?It should work. Working on fix.
@alexlamsl did you mean something like
var o = { key: fs.readFileSync("example.com.key"), ca: fs.readFileSync("example.com.crt") + "\n" + fs.readFileSync("intermediate.crt") };@fastner I just did it on the
crtfile itself:-----BEGIN CERTIFICATE----- (Your Primary SSL certificate: example.com.crt) -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- (Your Intermediate certificate: intermediate.crt) -----END CERTIFICATE-----And then specify only
certand nocain the options.@alexlamsl Your solution to concatenate cert and intermediates works well - thanks for the solution.
- added a commit that references this issue
on Nov 17, 2015 - added a commit that references this issue
on Jan 28, 2016 - added 3 commits that reference this issue
on Feb 11, 2016 Maybe it's a dumb question or the wrong place to ask, but is the
cert: cert+'\n'+caworkaround safe to use or do I have to be afraid that this causes trouble with future node versions?
Metadata
Metadata
Assignees
Labels
tlsIssues and PRs related to the tls subsystem.Issues and PRs related to the tls subsystem.
If I give key, cert and ca via options field to https.createServer the whole key chain is returned on connection (correct behaviour). If I try to do the same via SNICallback it is not possible to set whole key chain.
Example code:
Now try to connect via openssl:
Expected and real behaviour is
Verify return code: 0 (OK).If I remove the ca in options map like this
and rerun openssl client the return code is
Verify return code: 21 (unable to verify the first certificate)which indicates that not the whole key chain is returned.The expected behaviour is
Verify return code: 0 (OK)as the ca field is given totls.createSecureContext.This occures in io.js 3.x and Node.js 4.0.0.