Repository navigation
SSL core dump in v6.9.1 #9551
Description
Activity
- addedtlsIssues and PRs related to the tls subsystem.Issues and PRs related to the tls subsystem.c++Issues and PRs that require attention from people who are familiar with C++.Issues and PRs that require attention from people who are familiar with C++.
on Nov 11, 2016 /cc @indutny
@rdkgit can you provide a standalone example?
@rdkgit could you please provide a certificate chain that you used?
Here is an example I just now tested and it core dumps node when I connect to it using openssl s_client.
Test with: /bin/openssl s_client -connect hostname:8443// test.js // test to see if node core dumps var fs = require('fs'); var constants = require('constants'); var http = require('http'); var https = require('https'); var httpPort = 8080; var httpsPort = 8443; var sslOptions = { key: fs.readFileSync('/tmp/exterus-key.pem'), cert: fs.readFileSync('/tmp/exterus-cert.pem'), // startssl sub.class1.server.ca.pem append >> cert pem secureProtocol: 'SSLv23_method', secureOptions: constants.SSL_OP_NO_SSLv3 | constants.SSL_OP_NO_SSLv2, }; // set up proxy server and start listening!! http.createServer().listen(httpPort); console.log("Test listening on "+httpPort); https.createServer(sslOptions).listen(httpsPort); console.log("Test listening on "+httpsPort);
The cert I'm using is from startssl. Do you want me to send you the cert itself? Or, what kind of output would you like?
Thanks,
Bobby
@rdkgit may I ask you to put the
exterus-cert.pemcontents to https://gist.github.com/ ? It seems like it is crashing when it tries to encode the certificate chain, so having the full certificate chain may be a key to understanding the cause of the crash.OK, uploaded. Are you able to reference it? Sorry if thats a dumb question. Havent used this feature of github before.
rdkgit/exterus-cert.pemThanks! Here is the link: https://gist.github.com/rdkgit/130b3476d82a61fab9a2ed164ac102ee
@rdkgit have you built node.js from source? Or have you downloaded the binary?
I'm using the pre-built platform packages for both Fedora, RHEL, and Centos. It core dumps on my ec2 instance but not my Fedora desktop running older version of node.
Oh wait! I just realized that you are using shared openssl library:
/lib64/libssl.so.10. Do you know which version of OpenSSL that EC2 system has?OpenSSL 1.0.1e-fips 11 Feb 2013
On my Fedora system where no core dumps (but older nodejs version), I have 1.0.2h though.
@rdkgit what does
node -pe process.versions.opensslsay?8 remaining items
cc @sgallagher - maybe you can answer @rdkgit's question?
I'll close out the bug report since it's a downstream issue.
Thanks! Happy to provide any/all info to RH so we can fix this in the RHEL package.
Bobby
@rdkgit Where did you get the package for RHEL? Was it one provided by Red Hat Software Collections or was it something you got from Fedora EPEL (Extra Packages for Enterprise Linux)?
The former are supported by Red Hat, the latter are community-supported.
If you got it from EPEL, then you should file a bug at https://bugzilla.redhat.com/enter_bug.cgi?product=Fedora%20EPEL in the
nodejspackage.Please also include the full output of
rpm -q openssl(orrpm -q openssl-fipsif you're using that one). I should note that the EPEL version hasn't been tested with FIPS; we only expect it to work with the standard OpenSSL. It may be that Node.js is not FIPS-compatible.Hey. I believe it was from RHEL EPEL repo as I did not find it in the regular/default REPOs that were set up with my ec2 instance.
yum list nodejs
Loaded plugins: amazon-id, rhui-lb, search-disabled-repos
Available Packages
nodejs.x86_64 1:6.9.1-1.el7 epelI will file a bug via bugzilla.
Thanks,
Bobby
For what it's worth, I just tested this with:
openssl-libs-1.0.1e-51.el7_2.7.x86_64 nodejs-6.9.1-1.el7.x86_64I was unable to reproduce the issue in either FIPS or non-FIPS mode with that version of OpenSSL (the latest available on RHEL 7.2). Can you confirm that you're using the most recent version? Please provide the output of
rpm -q openssl-libs, @rdkgitHi!
The ec2 instance I'm running has RHEL 7.3 and the following:
openssl-libs-1.0.1e-60.el7.x86_64
npm-3.10.8-1.6.9.1.1.el7.x86_64
nodejs-6.9.1-1.el7.x86_64When I use this config, it core dumps reliably with my test program. I will create a bugzilla entry.
Thanks,
Bobby
@rdkgit Please include detailed information about how you generated the certificate in question (as in, exact steps). My guess is that there's something atypical about the certificate or its CA chain that's triggering a behavior I can't reproduce with a certificate generated the way I normally do.
Hi!
Here is the command I ran to generate the CSR. I then uploaded to startssl and got the cert.
/bin/openssl req -out exterus.csr -new -newkey rsa:2048 -nodes -keyout exterus.key
I generated the csr on my desktop fedora system using my local copy of openssl.
%/bin/openssl version
OpenSSL 1.0.2h-fips 3 May 2016Bobby
Update from bugzilla investigation. https://bugzilla.redhat.com/show_bug.cgi?id=1394948
My startssl cert .pem file also had the intermediate startssl cert appended to the end of it. Apparently, this is known to crash some revs of nodejs due to either openssl bug or bug in node code. Not sure. Either way, when I remove the intermediate cert (its not needed anyway), the problem goes away.
Thanks to all for the help resolving this.
Bobby
@rdkgit I can't comment on the bugzilla, but if they have questions about node, they should ask them here, I'm familiar with the referenced code.
Btw, I'm surprised you don't need the intermediate cert... how does the peer know your intermediate if you don't send it?
Hi!
I'm using the startcom class-1 server ca cert and that seems to make everyone happy. The convention that I understood is that one could append that the CA server cert to one's server cert. That works in other versions of node but this particular version of node core dumps. When I moved the start intermediate cert into the CA SSL option, everything worked.
Thanks,
Bobby
I can confirm this same issue. Have a very similar setup to the original one described and removing the second certificate in the chain did solve the issue. Seems to be a low level C library bug as reported on the redhat website.
Just for documentation sake, I had this issue with an EC2 instance, openssl and Let's Encrypt aswell:
segfault in libcrypto.so.1.0.1enpm-3.10.10-1.6.9.4.2.el7.x86_64 nodejs-6.9.4-2.el7.x86_64 openssl-1.0.1e-60.el7_3.1.x86_64
Replaced
fullchain.pembycert.pemin httpsOptions and everything worked out great.@yuriploc thanks for the suggestion, I replaced my
fullchain.pemfile withcert.pemand everything is working now (using CentOS 7 and Let's Encrypt certs).
Created simple https server and try to connect to it with various clients. node core dumps w/o any stack trace. GDB output below. Sorry if this is duplicate. I was not find anything related via searching. Code works fine on Fedora system running 4.6.1. Also, system it is core-dumping on is an EC2 instance thus virtual.