Re: Certification verification

Frediano Ziglio <[email protected]>
Newsgroups gmane.comp.db.tds.freetds
Message-ID <CAHt6W4cY62_bU6f_MWGoBkV2KfSc4ZwHUd7NHwE4buhpFc-0qQ@mail.gmail.com>
2015-04-06 16:54 GMT+01:00 Peter Deacon <[email protected]>:
> On Mon, 6 Apr 2015, Frediano Ziglio wrote:
>
>> Hi,
>>  this is my last stopover before release. I wrote a patch to start
>> doing certificate verification, see
>>
>> https://github.com/freddy77/freetds/commit/557caf0e0af1c385d6cfd1602f593f9683ed6fc8.
>>
>> Now the problem is when to check. If a mssql is installed without
>> certificate a dummy certificate (self signed with a
>> "Self_Signed_Fallback" common name) is generate every time the sql
>> instance is started (not during the install so you cannot cache the
>> certificate of a given server). So there is no way to check these
>> certificates, FreeTDS (and MSSQL driver too) has to accept by default
>> these certificates.
>> The patch add two options to freetds.conf, "ca file" and "crl file",
>> respectively the file containing the root authorities and the
>> certificates revocation list (list of certificates to not accept). So
>> the key of the patch is: if you specify CA list you want to check
>> certificate, if not accept any certificates sent. Now, the questions
>> are:
>
>
>> - should FreeTDS check the common name (with server name inside) of
>> the certificate?
>
>
> Important if a global CA is used.  Without checking an attacker can buy a
> cert from that CA and compromise security.
>
> Might also be important for company-wide CAs.  Company might hand out a cert
> for a test server in a satellite office that compromises an important
> production server without the name checking.
>

Mmm... perhaps would be nice to have a "ca files" instead with a list
of filenames like "file1:file2" were fileX is a file or "system" for
global system CAs.

> Ususally hostname TDS is using (e.g. sqlserver.mydomain.com) would match CN
> of servers public key.
>
> In OpenSSL after you SSL_accept connection fetching CN might look something
> like:
>
> peer = SSL_get_peer_certificate(myconnection);
> X509_NAME_get_text_by_NID(X509_get_subject_name(peer),NID_commonName,output_cn_goes_here...)
> X509_free(peer);
>
>
> Sometimes CN can contain wildcards *.mydomain.com or additional valid hosts
> present in subject alternate name attributes of servers public key.. not
> sure either is needed/useful here.
>
>> - should I add an option to disable name verification?
>

I think this can be useful, but default should be enabled.

>
>> - should I read system CA list so to check the global list installed
>> in the system? I don't know if this is useful, are mssql with proper
>> certificate using a public CA?
>
>
> Dunno might be useful for someone connecting to a commercially hosted
> server..?
>
> Have Fun!
> Peter

Thanks

Frediano
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.