Project

General

Profile

Bug #8536

tails-security-check fails open if passed an empty or otherwise useless CA file

Added by intrigeri about 5 years ago. Updated almost 5 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
-
Target version:
Start date:
01/06/2015
Due date:
% Done:

100%

Feature Branch:
bugfix/8536-security-check-CA-pinning
Type of work:
Code
Blueprint:
Starter:
Affected tool:
Security Check

Description

If I empty the CA bundle file passed to that script, it still manages to download the Atom feed without complaining.

Associated revisions

Revision 1f04b6d7
Added by Tails developers almost 5 years ago

Merge remote-tracking branch 'origin/bugfix/8536-security-check-CA-pinning' into devel

Fix-committed: #8536

History

#1 Updated by intrigeri about 5 years ago

  • Affected tool set to Security Check

#2 Updated by intrigeri almost 5 years ago

  • Subject changed from tails-security-check CA pinning doesn't work to tails-security-check fails open if passed an empty or otherwise useless CA file
  • Status changed from Confirmed to In Progress
  • % Done changed from 0 to 10
  • Feature Branch set to bugfix/8536-security-check-CA-pinning

Actually, it does work, as long as the specified CA file exists and is not empty. Unfortunately, the underlying HTTPS stack fails open when passed a non-existing or empty CA file. So I'm adding checks to ensure we fail close in such cases, and also so that I'm not confused about this next time.

#3 Updated by intrigeri almost 5 years ago

  • Assignee changed from intrigeri to anonym
  • % Done changed from 10 to 50
  • QA Check set to Ready for QA

#4 Updated by Tails almost 5 years ago

  • Status changed from In Progress to 11
  • % Done changed from 50 to 100

Applied in changeset commit:eb510638089736a52335ef1f91ab18d7894e3fec.

#5 Updated by anonym almost 5 years ago

  • Assignee deleted (anonym)
  • QA Check changed from Ready for QA to Pass

#6 Updated by BitingBird almost 5 years ago

  • Status changed from 11 to Resolved

Also available in: Atom PDF