RE: [EXTERNAL] Re: Using certificates and keys from a list
"'Martin Bonner' via openssl-users" <[email protected]> Thu, 9 Apr 2026 06:38:03 +0000
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <PH3PPF7A88A980A8CEDD2FBE1A2978C33E2F3582@PH3PPF7A88A980A.namprd11.prod.outlook.com> |
--_000_PH3PPF7A88A980A8CEDD2FBE1A2978C33E2F3582PH3PPF7A88A980A_ Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Yehbut: If an attacker can get code execution inside your app, you might th= ink they only have the access of the unprivileged user, but actually they j= ust have to do seteuid(0) and the world is their oyster. If an attacker can=E2=80=99t get code execution inside your app, then why b= other dropping to the unprivileged user at all? (One answer to that may be= , because the interactive user can tell the app to read and write files, an= d you want to limit that to the unprivileged user.) Martin Bonner From: [email protected] <[email protected]> On Behalf Of Do= ug Hardie Sent: 09 April 2026 01:40 To: Seo Suchan <[email protected]> Cc: [email protected] Subject: [EXTERNAL] Re: Using certificates and keys from a list > On Apr 8, 2026, at 16:=E2=80=8A37, Seo Suchan <tjtncks@=E2=80=8Agmail.=E2= =80=8Acom> wrote: > > Wouldn't it defeat perpose of dropping privilege in f= irst place if code can call function to raise its privilege back to root? >= > > On 2026=EB=85=84 4=EC=9B=94 9=EC=9D=BC > On Apr 8, 2026, at 16:37, Seo Suchan <[email protected]<mailto:tjtncks@gm= ail.com>> wrote: > > Wouldn't it defeat perpose of dropping privilege in first place if code c= an call function to raise its privilege back to root? > > > On 2026=EB=85=84 4=EC=9B=94 9=EC=9D=BC =EC=98=A4=EC=A0=84 7=EC=8B=9C 24= =EB=B6=84 14=EC=B4=88 GMT+09:00, Doug Hardie <[email protected]<mailto:bc979@l= afn.org>> =EC=9E=91=EC=84=B1=ED=95=A8: > I implemented all that code to load the certificates and keys and it work= ed just fine. However, once I set the keys to 0600, it no longer worked. Th= e reason is that the startup code that runs as root is quite small. It does= n't know which keys will be required. In fact, those keys might not even ex= ist yet. They can be added at any time. Hence, the app needs to read the ke= ys after the uid has been changed to the unprivileged uid. > > The solution turns out to be changing the setuid to seteuid to the unpriv= ileged user, and then when the connection is starting, in the SSL_CTX_set_c= lient_hello_cb routine, use seteuid (0) to go back to root. After the certi= ficate and key are loaded use seteuid to go back to the unprivileged user. = This is on FreeBSD. There is a similar, but different implementation for Li= nux. Not really. It only raises privilege for just enough time to read the cert= ificate and key. That code is checked by me to ensure it does nothing unus= ual. -- Doug -- You received this message because you are subscribed to the Google Groups "= openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org<mailto:openssl-users+unsubscr= [email protected]>. To view this discussion visit https://urldefense.com/v3/__https://groups.go= ogle.com/a/openssl.org/d/msgid/openssl-users/17570E38-919A-47D5-8DA0-53248D= 5DD490*40sermon-archive.info__;JQ!!FJ-Y8qCqXTj2!cOjW3cavmIqGSZDMJlh9jjTyLto= xc4ayzsyY5HoiOn6iLZp33GZ8kvjRuQfhwYPopJHSNzhFw7gyfh8$<https://urldefense.co= m/v3/__https:/groups.google.com/a/openssl.org/d/msgid/openssl-users/17570E3= 8-919A-47D5-8DA0-53248D5DD490*40sermon-archive.info__;JQ!!FJ-Y8qCqXTj2!cOjW= 3cavmIqGSZDMJlh9jjTyLtoxc4ayzsyY5HoiOn6iLZp33GZ8kvjRuQfhwYPopJHSNzhFw7gyfh8= $>. Any email and files/attachments transmitted with it are intended solely for= the use of the individual or entity to whom they are addressed. If this me= ssage has been sent to you in error, you must not copy, distribute or discl= ose of the information it contains. Please notify Entrust immediately and d= elete the message from your system. --=20 You received this message because you are subscribed to the Google Groups "= openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msg= id/openssl-users/PH3PPF7A88A980A8CEDD2FBE1A2978C33E2F3582%40PH3PPF7A88A980A= .namprd11.prod.outlook.com. --_000_PH3PPF7A88A980A8CEDD2FBE1A2978C33E2F3582PH3PPF7A88A980A_ Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr= osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:= //www.w3.org/TR/REC-html40"> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dutf-8"> <meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)"> <style><!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} @font-face {font-family:Aptos;} @font-face {font-family:Consolas; panose-1:2 11 6 9 2 2 4 3 2 4;} @font-face {font-family:"Malgun Gothic"; panose-1:2 11 5 3 2 0 0 2 0 4;} @font-face {font-family:"Gotham Book";} @font-face {font-family:"Arial Black"; panose-1:2 11 10 4 2 1 2 2 2 4;} @font-face {font-family:"\@Malgun Gothic";} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0cm; font-size:10.0pt; font-family:"Aptos",sans-serif;} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;} pre {mso-style-priority:99; mso-style-link:"HTML Preformatted Char"; margin:0cm; margin-bottom:.0001pt; font-size:10.0pt; font-family:"Courier New";} span.HTMLPreformattedChar {mso-style-name:"HTML Preformatted Char"; mso-style-priority:99; mso-style-link:"HTML Preformatted"; font-family:Consolas;} span.EmailStyle21 {mso-style-type:personal-reply; font-family:"Aptos",sans-serif; color:windowtext;} .MsoChpDefault {mso-style-type:export-only; font-size:10.0pt; mso-ligatures:none;} @page WordSection1 {size:612.0pt 792.0pt; margin:72.0pt 72.0pt 72.0pt 72.0pt;} div.WordSection1 {page:WordSection1;} --></style><!--[if gte mso 9]><xml> <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext=3D"edit"> <o:idmap v:ext=3D"edit" data=3D"1" /> </o:shapelayout></xml><![endif]--> </head> <body lang=3D"EN-GB" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:brea= k-word"> <div class=3D"WordSection1"> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;mso-fareast-language= :EN-US">Yehbut: If an attacker can get code execution inside your app, you = might think they only have the access of the unprivileged user, but actuall= y they just have to do seteuid(0) and the world is their oyster.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;mso-fareast-language= :EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;mso-fareast-language= :EN-US">If an attacker <i>can=E2=80=99t</i> get code execution inside your app, then why bother dr= opping to the unprivileged user at all? (One answer to that may be, b= ecause the interactive user can tell the app to read and write files, and y= ou want to limit that to the unprivileged user.)<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;mso-fareast-language= :EN-US"><o:p> </o:p></span></p> <table class=3D"MsoNormalTable" border=3D"0" cellspacing=3D"0" cellpadding= =3D"0" style=3D"border-collapse:collapse"> <tbody> <tr> <td width=3D"265" valign=3D"top" style=3D"width:198.8pt;padding:0cm 5.4pt 0= cm 5.4pt"> <p class=3D"MsoNormal" style=3D"margin-bottom:2.7pt;text-autospace:none"><s= pan lang=3D"EN-US" style=3D"font-size:14.0pt;font-family:"Arial Black&= quot;,sans-serif;color:#6F2176">Martin Bonner</span><span lang=3D"EN-US" st= yle=3D"font-size:14.0pt;font-family:"Gotham Book";color:#6F2176;m= so-fareast-language:EN-US"><o:p></o:p></span></p> </td> </tr> </tbody> </table> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;mso-fareast-language= :EN-US"><o:p> </o:p></span></p> <div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm = 0cm 0cm"> <p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:11.0pt;fo= nt-family:"Calibri",sans-serif">From:</span></b><span lang=3D"EN-= US" style=3D"font-size:11.0pt;font-family:"Calibri",sans-serif"> = [email protected] <[email protected]> <b>On Behalf Of </b>Doug Hardie<br> <b>Sent:</b> 09 April 2026 01:40<br> <b>To:</b> Seo Suchan <[email protected]><br> <b>Cc:</b> [email protected]<br> <b>Subject:</b> [EXTERNAL] Re: Using certificates and keys from a list<o:p>= </o:p></span></p> </div> <p class=3D"MsoNormal"><o:p> </o:p></p> <div> <p class=3D"MsoNormal" style=3D"mso-line-height-alt:.75pt"><span style=3D"f= ont-size:1.0pt;color:white">> On Apr 8, 2026, at 16:</span><span style= =3D"font-size:1.0pt;font-family:"Arial",sans-serif;color:white">= =E2=80=8A</span><span style=3D"font-size:1.0pt;color:white">37, Seo Suchan <tjtncks@</span><span style=3D"font-size:1.0pt;font-family:"= ;Arial",sans-serif;color:white">=E2=80=8A</span><span style=3D"font-si= ze:1.0pt;color:white">gmail.</span><span style=3D"font-size:1.0pt;font-fami= ly:"Arial",sans-serif;color:white">=E2=80=8A</span><span style=3D= "font-size:1.0pt;color:white">com> wrote: > > Wouldn't it defeat perpose of dropping privilege in first= place if code can call function to raise its privilege back to root? > = > > On 2026</span><span style=3D"font-size:1.0pt;font-family:"Ma= lgun Gothic",sans-serif;color:white">=EB=85=84</span><span style=3D"fo= nt-size:1.0pt;color:white"> 4</span><span style=3D"font-size:1.0pt;font-family:"Malgun Gothic&quo= t;,sans-serif;color:white">=EC=9B=94</span><span style=3D"font-size:1.0pt;c= olor:white"> 9</span><span style=3D"font-size:1.0pt;font-family:"Malgu= n Gothic",sans-serif;color:white">=EC=9D=BC</span><span style=3D"font-= size:1.0pt;color:white"><o:p></o:p></span></p> </div> <div> <p class=3D"MsoNormal" style=3D"mso-line-height-alt:.75pt"><span style=3D"f= ont-size:1.0pt;color:white"><o:p></o:p></span></p> </div> <pre style=3D"white-space:pre-wrap"><span style=3D"font-size:12.0pt;font-fa= mily:"Arial",sans-serif">> On Apr 8, 2026, at 16:37, Seo Sucha= n <<a href=3D"mailto:[email protected]">[email protected]</a>> wrote:= <o:p></o:p></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if">> <o:p></o:p></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if">> Wouldn't it defeat perpose of dropping privilege in first place if= code can call function to raise its privilege back to root?<o:p></o:p></sp= an></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if">> <o:p></o:p></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if">> <o:p></o:p></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if">> On 2026</span><span style=3D"font-size:12.0pt;font-family:"Ma= lgun Gothic",sans-serif">=EB=85=84</span><span style=3D"font-size:12.0= pt;font-family:"Arial",sans-serif"> 4</span><span style=3D"font-s= ize:12.0pt;font-family:"Malgun Gothic",sans-serif">=EC=9B=94</spa= n><span style=3D"font-size:12.0pt;font-family:"Arial",sans-serif"= > 9</span><span style=3D"font-size:12.0pt;font-family:"Malgun Gothic&q= uot;,sans-serif">=EC=9D=BC</span><span style=3D"font-size:12.0pt;font-famil= y:"Arial",sans-serif"> </span><span style=3D"font-size:12.0pt;fon= t-family:"Malgun Gothic",sans-serif">=EC=98=A4=EC=A0=84</span><sp= an style=3D"font-size:12.0pt;font-family:"Arial",sans-serif"> 7</= span><span style=3D"font-size:12.0pt;font-family:"Malgun Gothic",= sans-serif">=EC=8B=9C</span><span style=3D"font-size:12.0pt;font-family:&qu= ot;Arial",sans-serif"> 24</span><span style=3D"font-size:12.0pt;font-f= amily:"Malgun Gothic",sans-serif">=EB=B6=84</span><span style=3D"= font-size:12.0pt;font-family:"Arial",sans-serif"> 14</span><span = style=3D"font-size:12.0pt;font-family:"Malgun Gothic",sans-serif"= >=EC=B4=88</span><span style=3D"font-size:12.0pt;font-family:"Arial&qu= ot;,sans-serif"> GMT+09:00, Doug Hardie <<a href=3D"mailto:[email protected]= g">[email protected]</a>> </span><span style=3D"font-size:12.0pt;font-famil= y:"Malgun Gothic",sans-serif">=EC=9E=91=EC=84=B1=ED=95=A8</span><= span style=3D"font-size:12.0pt;font-family:"Arial",sans-serif">:<= o:p></o:p></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if">> I implemented all that code to load the certificates and keys and = it worked just fine. However, once I set the keys to 0600, it no longer wor= ked. The reason is that the startup code that runs as root is quite small. = It doesn't know which keys will be required. In fact, those keys might not = even exist yet. They can be added at any time. Hence, the app needs to read= the keys after the uid has been changed to the unprivileged uid.<o:p></o:p= ></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if">> <o:p></o:p></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if">> The solution turns out to be changing the setuid to seteuid to the= unprivileged user, and then when the connection is starting, in the SSL_CT= X_set_client_hello_cb routine, use seteuid (0) to go back to root. After th= e certificate and key are loaded use seteuid to go back to the unprivileged= user. This is on FreeBSD. There is a similar, but different implementation= for Linux.<o:p></o:p></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if"><o:p> </o:p></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if">Not really. It only raises privilege for just enough time to read= the certificate and key. That code is checked by me to ensure it doe= s nothing unusual.<o:p></o:p></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if"><o:p> </o:p></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if">-- Doug<o:p></o:p></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if"><o:p> </o:p></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if"><o:p> </o:p></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if">-- <o:p></o:p></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if">You received this message because you are subscribed to the Google Grou= ps "openssl-users" group.<o:p></o:p></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if">To unsubscribe from this group and stop receiving emails from it, send = an email to <a href=3D"mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org">openss= [email protected]</a>.<o:p></o:p></span></pre> <pre><span style=3D"font-size:12.0pt;font-family:"Arial",sans-ser= if">To view this discussion visit <a href=3D"https://urldefense.com/v3/__ht= tps:/groups.google.com/a/openssl.org/d/msgid/openssl-users/17570E38-919A-47= D5-8DA0-53248D5DD490*40sermon-archive.info__;JQ!!FJ-Y8qCqXTj2!cOjW3cavmIqGS= ZDMJlh9jjTyLtoxc4ayzsyY5HoiOn6iLZp33GZ8kvjRuQfhwYPopJHSNzhFw7gyfh8$">https:= //urldefense.com/v3/__https://groups.google.com/a/openssl.org/d/msgid/opens= sl-users/17570E38-919A-47D5-8DA0-53248D5DD490*40sermon-archive.info__;JQ!!F= J-Y8qCqXTj2!cOjW3cavmIqGSZDMJlh9jjTyLtoxc4ayzsyY5HoiOn6iLZp33GZ8kvjRuQfhwYP= opJHSNzhFw7gyfh8$</a>.<o:p></o:p></span></pre> </div> <i>Any email and files/attachments transmitted with it are intended solely = for the use of the individual or entity to whom they are addressed. If this= message has been sent to you in error, you must not copy, distribute or di= sclose of the information it contains. <u>Please notify Entrust immediately and delete the message from your syste= m.</u></i><br> <br> </body> </html> <p></p> -- <br /> You received this message because you are subscribed to the Google Groups &= quot;openssl-users" group.<br /> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org">openssl-us= [email protected]</a>.<br /> To view this discussion visit <a href=3D"https://groups.google.com/a/openss= l.org/d/msgid/openssl-users/PH3PPF7A88A980A8CEDD2FBE1A2978C33E2F3582%40PH3P= PF7A88A980A.namprd11.prod.outlook.com?utm_medium=3Demail&utm_source=3Dfoote= r">https://groups.google.com/a/openssl.org/d/msgid/openssl-users/PH3PPF7A88= A980A8CEDD2FBE1A2978C33E2F3582%40PH3PPF7A88A980A.namprd11.prod.outlook.com<= /a>.<br /> --_000_PH3PPF7A88A980A8CEDD2FBE1A2978C33E2F3582PH3PPF7A88A980A_--