Ticket #599 (closed patch: fixed)

Opened 4 years ago

Last modified 7 months ago

Munin should be able to check the Subject DN in an X.509 Certificate when doing SSL/TLS

Reported by: e_tews Assigned to: nobody
Priority: normal Milestone: Z-later
Component: master Version: 1.3.4
Severity: major Keywords: ssl, tls, certificate, sdn
Cc:

Description

Hi

I would like to configure munin in a way, so that the SDN in an X.509 certificate is checked, when doing SSL/TLS. Just having a certificate signed by a CA is not sufficient. I have written a patch for that.

The patch contains some debugging output which can be removed.

Attachments

munin-tls-sdn.patch (6.4 kB) - added by e_tews on 05/26/08 14:17:24.

Change History

05/26/08 14:17:24 changed by e_tews

  • attachment munin-tls-sdn.patch added.

08/24/09 13:27:25 changed by janl

  • owner changed from nobody to kjellm.

We want this. Unfortunately it's too hard for myself to integrate it into the current trunk. Deferring.

08/24/09 13:28:07 changed by janl

  • type changed from enhancement to patch.
  • milestone set to Munin 1.4.

11/15/09 00:00:30 changed by janl

  • milestone changed from Munin 1.4 to Munin 1.5.

01/18/10 13:27:02 changed by janl

  • owner changed from kjellm to nobody.

02/25/10 00:59:31 changed by snide

  • milestone changed from Munin 1.5 to Z-later.

Pushing it for a later time since I don't know how to handle it for 1.5.

If someone has the skill to test/integrate the provided patch, he just has to set the correct milestone.

04/13/10 02:13:39 changed by bldewolf

  • status changed from new to closed.
  • resolution set to fixed.

Unfortunately, SSLeay is working against us when we try to do this. The patch that's submitted adds the code for verifying the SDN to the verify_certificate callback because that is where we can access the client certificate and choose specific fields. Unfortunately, this callback is used for both the local and remote certs, so this check could potentially fail on the local cert and mark the remote cert as untrusted.

Outside of the callback, I can't find a way to retrieve just the SDN or certain parts of the cert. I was hoping to be able to make a directive for matching just the CN, or verifying the CN matches reverse DNS, but I can't find any functions in SSLeay for inspection of certificates from the data structures available outside of the verification callback.

The best I can find is the dump certificate string, which does contain the SDN along with the Issuer DN. In r3483, I've added a directive named "tls_match" which is a regex applied to this string if it exists. In this way, one can match on the SDN. I've added more detail to the man page for munin.conf and munin-node.conf.

10/27/11 11:45:11 changed by junghatete1971

Anybody who loves films is more likely to love film downloads, too. The actual fact is that this pattern is becoming an enormous one and it's great for many who wish to create giant collections without having to dole out prime dollar or premium home area to do so. How to download from vimeo at the moment are out there legally from all sorts of huge film studios and even television networks, as well. A video assortment created digitally has an a variety of benefits over common disk purchases, too. The most important perks of video downloads contain the storage issues and pricing. But, why? Video downloads are usually a couple of dollars or extra less than a regular DVD buy as a result of there is no packaging issues to contend with. Plus, there's the straightforward truth delivery isn't a problem either. Since the companies that promote downloads save on transport and the film studios save on packaging, they can cross on some of these savings on to buyers. In regard to storage, it's a simple fact of space. It's a whole lot easier to store movies on a pc drive or a backup drive than it is to hold a hundred movies in a room. There is no need for shelf after shelf or tons of DVD towers when a set is created via video download. Management of movies and television downloads generally is a entire lot easier, too. It's pretty easy to create folders on the pc to store films by genre and it is a whole lot quicker, too. Video downloads are becoming the favorites of many for a motive past storage or pricing. This motive is variety. The very fact is the sorts of downloads accessible could be actually mind boggling. Let's take a look at what kinds of video downloads could be found legally: Hit films Just about every new film that hits the theaters will end up in a authorized obtain format shortly after release. This implies there is not any have to run to the video store, or worse, pay high greenback at a theater to see a brand new release. Television applications video downloading As the film studios soar on the bandwagon, so too are the tv studios. Hit exhibits from all many years might be discovered by the season or by the episode by way of video download.Classics As the movie download business becomes extra well-liked, many studios are video via their catalogues and offering downloads of their older movies. From the classics of the Nineteen Twenties to holiday favorites of the Nineteen Eighties, they'll all be found via video download. And, if a title can't be found right now, it is possible it is going to be added soon as each main film studio falls into place providing downloads by way of various totally different sites. Video downloads present their customers with an on demand facet, price financial savings and storage challenge discount that common DVD buys cannot. As this new format turns into more and more accepted, it is turning into the method of choice for getting and watching movies. Authentic works There are tons of areas to get video downloads from novice or little recognized creators. These movies might not have the financial backing of a few of the major movies in history, but that doesn't mean there isn't some good leisure out there. Indie works are getting a complete new viewers due to video downloads and the Internet.