Https - #7
Merged
Merged
Https#7
Conversation
SslStream and the BCL's cryptography call OpenSSL, which a Cosmos kernel does not have, so https:// runs TLS 1.3 or 1.2 through BouncyCastle.Cryptography 2.7.0 in its non-blocking mode: the protocol is handed what the socket received and asked for what to send, so the socket keeps being read through Available, Receive(byte[]) and Poll, and a request still never blocks the thread it runs on. The client offers ECDHE (X25519, P-256, P-384) with AES-GCM, ChaCha20-Poly1305 (first when the CPU has no AES instructions, as on a Cosmos kernel) and, for old TLS 1.2 servers, AES-CBC; it sends SNI and asks for http/1.1 through ALPN. The server's certificate must chain to one of Mozilla's roots, embedded from curl's cacert.pem (MPL 2.0, see THIRD-PARTY-NOTICES.txt): every link signed by the next with SHA-2 or EdDSA, RSA keys of 2048 bits at least, authorities allowed to issue what they issued (basic constraints, path length, key usage, extended key usage, name constraints, the host included), no critical extension that is not understood, and a subject alternative name for the host. The dates are checked last, so a date error means nothing else is wrong. HttpRequest.ServerCertificateValidation decides instead when set, given a ServerCertificate with the chain, its SHA-256 fingerprint and the built-in check's error. Redirects from https:// to http:// are not followed, and a redirect to another server no longer sends the Authorization, Proxy-Authorization, Cookie and Host headers set by hand. Version 2.1.0.
The test server can speak TLS through the desktop's SslStream, with certificates TestPki makes up: P-256 or RSA keys, SHA-2 or SHA-1 signatures, name constraints and broken chains of every kind. The tests cover TLS 1.3 and 1.2 with ECDSA and RSA chains, SNI and ALPN, chunked and large bodies, close_notify ending a body while the connection stays open, a close without close_notify, a cut-short body, POST, the redirect rules, the validation callback, and handshake failures and timeouts. CertificateValidator is tested chain by chain without a connection.
What the client offers, which certificates it trusts and why it refuses the others, ServerCertificateValidation, the redirect rules, what a Cosmos kernel needs (a RandomNumberGenerator plug, whether it asks for https:// or not, and a right clock), the limits, and the licenses of BouncyCastle and of the embedded Mozilla roots.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.