Skip to content

Fixes 500 error when using PKI authentication with an incomplete certificate chain - #86700

Merged
jportner merged 5 commits into
elastic:masterfrom
jportner:issue-77121-improve-delegated-pki
Jan 6, 2021
Merged

jportner merged 5 commits into
elastic:masterfrom
jportner:issue-77121-improve-delegated-pki

Conversation

@jportner

Copy link
Copy Markdown
Contributor

Fixes #77121.

@jportner
jportner marked this pull request as ready for review December 22, 2020 15:20
@jportner
jportner requested a review from a team as a code owner December 22, 2020 15:20
@azasypkin

Copy link
Copy Markdown
Contributor

ACK: will review tomorrow

@azasypkin
azasypkin self-requested a review December 28, 2020 14:08

@azasypkin azasypkin left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code LGTM, but I didn't manage to reproduce this issue in 7.9.3 locally (either I messed up with the certificates somehow or the behavior is different on Linux). Would you mind sharing the temp certificates you used to test this?

valid_to: validTo,
} = peerCertificate;

let issuerCertType: string;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: would you mind adding a comment here explaining why we do this and what every "type" means?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done in f2c3f3c.

FWIW, I don't think there is ever a case where a peer certificate has a null issuerCertificate value. At least, I haven't been able to reproduce that locally.

However, the way the getCertificateChain method was written previously, if the authentication process made it to this step and the peer certificate was valid but had a null issuerCertificate value, Kibana would allow the authentication attempt to proceed. I didn't want to change that behavior and potentially introduce a regression, but I can't be sure if we would encounter a null value or not, seeing as we are encountering undefined values when we shouldn't be.

Comment thread x-pack/plugins/security/server/authentication/providers/pki.ts Outdated
@jportner

jportner commented Jan 5, 2021

Copy link
Copy Markdown
Contributor Author

@elasticmachine merge upstream

@kibanamachine

Copy link
Copy Markdown
Contributor

💚 Build Succeeded

Metrics [docs]

Distributable file count

id before after diff
default 47253 48013 +760

History

To update your PR or re-run it, just comment with:
@elasticmachine merge upstream

@azasypkin azasypkin left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great, thanks! Used your certificates to confirm the error in 7.9 and that the issue doesn't happen now.

valid_to: validTo,
} = peerCertificate;

// The issuerCertificate field can be three different values:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❤️

@jportner
jportner merged commit e68d9f3 into elastic:master Jan 6, 2021
@jportner
jportner deleted the issue-77121-improve-delegated-pki branch January 6, 2021 14:00
jportner added a commit that referenced this pull request Jan 6, 2021
jportner added a commit that referenced this pull request Jan 6, 2021
jportner added a commit that referenced this pull request Jan 6, 2021
patrykkopycinski pushed a commit to patrykkopycinski/kibana that referenced this pull request May 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Make delegated PKI authentication more robust

3 participants