Skip to content

internal: TLS P2 harden (fork CI only) - #6

Open
songzhendong wants to merge 3 commits into
masterfrom
feat/grpc-http-tls-mtls-p2
Open

internal: TLS P2 harden (fork CI only)#6
songzhendong wants to merge 3 commits into
masterfrom
feat/grpc-http-tls-mtls-p2

Conversation

@songzhendong

Copy link
Copy Markdown
Owner

Summary

Note

Fork CI only — do not merge to apache. Official PR remains on feat/grpc-http-tls-mtls.

Test plan

  • unittest tests.unit.test_tls (33 ok, 2 skipped on Windows symlinks)
  • Fork CI green

Add SW_AGENT_FORCE_TLS and SSL CA/cert/key paths; share tls helpers across
gRPC and HTTP; convert PKCS#1 keys to PKCS#8 for HTTP stacks that reject
PKCS#1. Follow symlinks so Kubernetes secret mounts work. Never raise TLS
misconfig into the host process: warn and degrade (plaintext / system trust /
one-way TLS), including OSError from SSLContext load races and path
expanduser/resolve failures. Validate CA and client PEMs when building
material so bad content does not defer failure to connect time; FORCE_TLS
fallback never attaches client certs, and credential build failure may warn
and stay plaintext rather than abort start. Keep HTTP mTLS temp PEMs
fork-safe via register_at_fork rebind. Drop test-only
ssl_target_name_override; TLS peer-name follows grpc.default_authority.
Generate e2e PEMs via shared gen-e2e-tls-certs.sh in digest-pinned
alpine/openssl (no apk; PEMs not committed). mTLS e2e healthchecks the
sharing-server port.
Extract PKCS#1 / CERTIFICATE PEM between BEGIN/END only so preamble and
UTF-8 BOM cannot break b64decode or aio SSLContext cadata. Always verify
HTTP with a process-lifetime CA temp snapshot (not the resolved K8s
..data path) so secret rotation cannot invalidate an open session.
When the HTTP CA snapshot cannot be written, fall back to the still-readable
configured CA path instead of Requests' system trust store. Extract both
CERTIFICATE and TRUSTED CERTIFICATE blocks (labels/trust attrs preserved) so
openssl -trustout CAs remain usable for sync HTTPS; aio falls back to cafile
when cadata rejects TRUSTED CERTIFICATE.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant