fix(tls): generate MITM certificates accepted by strict X509 clients - #264
Conversation
Set leaf Authority Key Identifier and CA keyCertSign/cRLSign usages. Add a real local HTTPS probe with Python strict verification and synthetic credential injection; do not weaken client verification.
congwang-mk
left a comment
There was a problem hiding this comment.
Thanks, the fix itself looks right. rcgen's from_ca_cert_pem keeps the CA's SKI as PreSpecified, so the leaf AKI also matches bring-your-own CAs.
The test needs rework though:
-
Location. This belongs in
crates/sandlock-core/tests/integration/(registered intests/integration.rs), next totest_http_acl.rsandtest_http_inject_ca.rs. The bug is in core and nothing here is CLI specific. Please useSandbox::builder()with inlinepython3 -c, and no standalone.pyfile. -
No upstream needed. Strict verification fails during the client handshake with the proxy, before anything goes upstream. Allow
GET allowed.test/*, inject the CA into a temp bundle, and have the sandboxed Python client (VERIFY_X509_STRICT) fetchhttps://denied.test/. Then assert it gets a 403 rather thanSSLCertVerificationError. That removes theopensslCLI, the Debian-only/etc/ssl/certs/ca-certificates.crtpath, the upstream certs and theSSL_CERT_FILEoverride, which would leak across tests if the supervisor runs in the test process. HTTPS credential injection end to end is a separate follow-up (see the note at the end oftest_http_acl.rs). -
Unit test. Please add one in
transparent_proxy/tls.rsthat parses the minted leaf and CA withx509-parser(as a dev-dependency). It should assert that the leaf AKI equals the CA SKI and that the CA key usage includeskeyCertSign. That guards the fix on any host with no external tools.
Exercise Sandbox MITM with an injected temporary CA bundle and assert the exact local HTTP ACL denial. Add production-minted certificate AKI/SKI and CA keyCertSign assertions using x509-parser. Validated on Linux ARM64 with Python 3.13.3/OpenSSL 3.4.1, including independent AKI and key-usage red/green mutations. Focused tests pass. The full workspace suite reproduces the same four failures as pristine PR head; repository-wide formatting also has baseline failures.
|
Hi, Thanks for the detailed review. I’ve completed the requested revisions locally. They have not been pushed The changes address all three points:
Validation On Linux ARM64, Landlock ABI 8, Python 3.13.3 and OpenSSL 3.4.1:
The full workspace suite is not entirely green locally: 1682 passed, 4 failed, 8 ignored. The identical HTTPS credential injection E2E remains a separate follow-up, as requested. PR #265 is untouched. |
Closes #263.
Changes
use_authority_key_identifier_extensionon generated MITM leaf certificates.KeyCertSignandCrlSignusages on the generated CA. Adding only AKIexposes the next strict-verification error: missing CA key usage.
synthetic bearer credential and Python
VERIFY_X509_STRICT.No client-verification bypass, dependency update, global trust-store edit or
policy change. Caller-provided CAs are not rewritten to add missing extensions.
Validation
Executed on Ubuntu 25.04 ARM64, Linux 7.0.14 (OrbStack), Landlock ABI 8,
Python 3.13.3, OpenSSL 3.4.1:
cargo test --release -p sandlock-cli --test strict_tls: 1 passed.cargo test --release -p sandlock-core --lib transparent_proxy:: -- --test-threads=1: 8 passed.The integration test requires Python, OpenSSL CLI and the Debian-style system
CA bundle. It uses no public network service or production credential.
This PR does not enforce HTTPS-only credential injection and does not claim
validation of every cloud SDK or other CPU architecture.