RE: [EXTERNAL] Re: Using certificates and keys from a list

"'Martin Bonner' via openssl-users" <[email protected]> Thu, 9 Apr 2026 06:38:03 +0000
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <PH3PPF7A88A980A8CEDD2FBE1A2978C33E2F3582@PH3PPF7A88A980A.namprd11.prod.outlook.com>
--_000_PH3PPF7A88A980A8CEDD2FBE1A2978C33E2F3582PH3PPF7A88A980A_
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Yehbut: If an attacker can get code execution inside your app, you might th=
ink they only have the access of the unprivileged user, but actually they j=
ust have to do seteuid(0) and the world is their oyster.

If an attacker can=E2=80=99t get code execution inside your app, then why b=
other dropping to the unprivileged user at all?  (One answer to that may be=
, because the interactive user can tell the app to read and write files, an=
d you want to limit that to the unprivileged user.)

Martin Bonner


From: [email protected] <[email protected]> On Behalf Of Do=
ug Hardie
Sent: 09 April 2026 01:40
To: Seo Suchan <[email protected]>
Cc: [email protected]
Subject: [EXTERNAL] Re: Using certificates and keys from a list

> On Apr 8, 2026, at 16:=E2=80=8A37, Seo Suchan <tjtncks@=E2=80=8Agmail.=E2=
=80=8Acom> wrote: > > Wouldn't it defeat perpose of dropping privilege in f=
irst place if code can call function to raise its privilege back to root? >=
 > > On 2026=EB=85=84 4=EC=9B=94 9=EC=9D=BC


> On Apr 8, 2026, at 16:37, Seo Suchan <[email protected]<mailto:tjtncks@gm=
ail.com>> wrote:

>

> Wouldn't it defeat perpose of dropping privilege in first place if code c=
an call function to raise its privilege back to root?

>

>

> On 2026=EB=85=84 4=EC=9B=94 9=EC=9D=BC =EC=98=A4=EC=A0=84 7=EC=8B=9C 24=
=EB=B6=84 14=EC=B4=88 GMT+09:00, Doug Hardie <[email protected]<mailto:bc979@l=
afn.org>> =EC=9E=91=EC=84=B1=ED=95=A8:

> I implemented all that code to load the certificates and keys and it work=
ed just fine. However, once I set the keys to 0600, it no longer worked. Th=
e reason is that the startup code that runs as root is quite small. It does=
n't know which keys will be required. In fact, those keys might not even ex=
ist yet. They can be added at any time. Hence, the app needs to read the ke=
ys after the uid has been changed to the unprivileged uid.

>

> The solution turns out to be changing the setuid to seteuid to the unpriv=
ileged user, and then when the connection is starting, in the SSL_CTX_set_c=
lient_hello_cb routine, use seteuid (0) to go back to root. After the certi=
ficate and key are loaded use seteuid to go back to the unprivileged user. =
This is on FreeBSD. There is a similar, but different implementation for Li=
nux.



Not really.  It only raises privilege for just enough time to read the cert=
ificate and key.  That code is checked by me to ensure it does nothing unus=
ual.



-- Doug





--

You received this message because you are subscribed to the Google Groups "=
openssl-users" group.

To unsubscribe from this group and stop receiving emails from it, send an e=
mail to openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org<mailto:openssl-users+unsubscr=
[email protected]>.

To view this discussion visit https://urldefense.com/v3/__https://groups.go=
ogle.com/a/openssl.org/d/msgid/openssl-users/17570E38-919A-47D5-8DA0-53248D=
5DD490*40sermon-archive.info__;JQ!!FJ-Y8qCqXTj2!cOjW3cavmIqGSZDMJlh9jjTyLto=
xc4ayzsyY5HoiOn6iLZp33GZ8kvjRuQfhwYPopJHSNzhFw7gyfh8$<https://urldefense.co=
m/v3/__https:/groups.google.com/a/openssl.org/d/msgid/openssl-users/17570E3=
8-919A-47D5-8DA0-53248D5DD490*40sermon-archive.info__;JQ!!FJ-Y8qCqXTj2!cOjW=
3cavmIqGSZDMJlh9jjTyLtoxc4ayzsyY5HoiOn6iLZp33GZ8kvjRuQfhwYPopJHSNzhFw7gyfh8=
$>.

Any email and files/attachments transmitted with it are intended solely for=
 the use of the individual or entity to whom they are addressed. If this me=
ssage has been sent to you in error, you must not copy, distribute or discl=
ose of the information it contains. Please notify Entrust immediately and d=
elete the message from your system.

--=20
You received this message because you are subscribed to the Google Groups "=
openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msg=
id/openssl-users/PH3PPF7A88A980A8CEDD2FBE1A2978C33E2F3582%40PH3PPF7A88A980A=
.namprd11.prod.outlook.com.

--_000_PH3PPF7A88A980A8CEDD2FBE1A2978C33E2F3582PH3PPF7A88A980A_
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dutf-8">
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Aptos;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
	{font-family:"Malgun Gothic";
	panose-1:2 11 5 3 2 0 0 2 0 4;}
@font-face
	{font-family:"Gotham Book";}
@font-face
	{font-family:"Arial Black";
	panose-1:2 11 10 4 2 1 2 2 2 4;}
@font-face
	{font-family:"\@Malgun Gothic";}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	font-size:10.0pt;
	font-family:"Aptos",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0cm;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:Consolas;}
span.EmailStyle21
	{mso-style-type:personal-reply;
	font-family:"Aptos",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;
	mso-ligatures:none;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-GB" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:brea=
k-word">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;mso-fareast-language=
:EN-US">Yehbut: If an attacker can get code execution inside your app, you =
might think they only have the access of the unprivileged user, but actuall=
y they just have to do seteuid(0) and
 the world is their oyster.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;mso-fareast-language=
:EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;mso-fareast-language=
:EN-US">If an attacker
<i>can=E2=80=99t</i> get code execution inside your app, then why bother dr=
opping to the unprivileged user at all?&nbsp; (One answer to that may be, b=
ecause the interactive user can tell the app to read and write files, and y=
ou want to limit that to the unprivileged user.)<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;mso-fareast-language=
:EN-US"><o:p>&nbsp;</o:p></span></p>
<table class=3D"MsoNormalTable" border=3D"0" cellspacing=3D"0" cellpadding=
=3D"0" style=3D"border-collapse:collapse">
<tbody>
<tr>
<td width=3D"265" valign=3D"top" style=3D"width:198.8pt;padding:0cm 5.4pt 0=
cm 5.4pt">
<p class=3D"MsoNormal" style=3D"margin-bottom:2.7pt;text-autospace:none"><s=
pan lang=3D"EN-US" style=3D"font-size:14.0pt;font-family:&quot;Arial Black&=
quot;,sans-serif;color:#6F2176">Martin Bonner</span><span lang=3D"EN-US" st=
yle=3D"font-size:14.0pt;font-family:&quot;Gotham Book&quot;;color:#6F2176;m=
so-fareast-language:EN-US"><o:p></o:p></span></p>
</td>
</tr>
</tbody>
</table>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;mso-fareast-language=
:EN-US"><o:p>&nbsp;</o:p></span></p>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:11.0pt;fo=
nt-family:&quot;Calibri&quot;,sans-serif">From:</span></b><span lang=3D"EN-=
US" style=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,sans-serif"> =
[email protected] &lt;[email protected]&gt;
<b>On Behalf Of </b>Doug Hardie<br>
<b>Sent:</b> 09 April 2026 01:40<br>
<b>To:</b> Seo Suchan &lt;[email protected]&gt;<br>
<b>Cc:</b> [email protected]<br>
<b>Subject:</b> [EXTERNAL] Re: Using certificates and keys from a list<o:p>=
</o:p></span></p>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<p class=3D"MsoNormal" style=3D"mso-line-height-alt:.75pt"><span style=3D"f=
ont-size:1.0pt;color:white">&gt; On Apr 8, 2026, at 16:</span><span style=
=3D"font-size:1.0pt;font-family:&quot;Arial&quot;,sans-serif;color:white">=
=E2=80=8A</span><span style=3D"font-size:1.0pt;color:white">37, Seo
 Suchan &lt;tjtncks@</span><span style=3D"font-size:1.0pt;font-family:&quot=
;Arial&quot;,sans-serif;color:white">=E2=80=8A</span><span style=3D"font-si=
ze:1.0pt;color:white">gmail.</span><span style=3D"font-size:1.0pt;font-fami=
ly:&quot;Arial&quot;,sans-serif;color:white">=E2=80=8A</span><span style=3D=
"font-size:1.0pt;color:white">com&gt;
 wrote: &gt; &gt; Wouldn't it defeat perpose of dropping privilege in first=
 place if code can call function to raise its privilege back to root? &gt; =
&gt; &gt; On 2026</span><span style=3D"font-size:1.0pt;font-family:&quot;Ma=
lgun Gothic&quot;,sans-serif;color:white">=EB=85=84</span><span style=3D"fo=
nt-size:1.0pt;color:white">
 4</span><span style=3D"font-size:1.0pt;font-family:&quot;Malgun Gothic&quo=
t;,sans-serif;color:white">=EC=9B=94</span><span style=3D"font-size:1.0pt;c=
olor:white"> 9</span><span style=3D"font-size:1.0pt;font-family:&quot;Malgu=
n Gothic&quot;,sans-serif;color:white">=EC=9D=BC</span><span style=3D"font-=
size:1.0pt;color:white"><o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"mso-line-height-alt:.75pt"><span style=3D"f=
ont-size:1.0pt;color:white"><o:p></o:p></span></p>
</div>
<pre style=3D"white-space:pre-wrap"><span style=3D"font-size:12.0pt;font-fa=
mily:&quot;Arial&quot;,sans-serif">&gt; On Apr 8, 2026, at 16:37, Seo Sucha=
n &lt;<a href=3D"mailto:[email protected]">[email protected]</a>&gt; wrote:=
<o:p></o:p></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if">&gt; <o:p></o:p></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if">&gt; Wouldn't it defeat perpose of dropping privilege in first place if=
 code can call function to raise its privilege back to root?<o:p></o:p></sp=
an></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if">&gt; <o:p></o:p></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if">&gt; <o:p></o:p></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if">&gt; On 2026</span><span style=3D"font-size:12.0pt;font-family:&quot;Ma=
lgun Gothic&quot;,sans-serif">=EB=85=84</span><span style=3D"font-size:12.0=
pt;font-family:&quot;Arial&quot;,sans-serif"> 4</span><span style=3D"font-s=
ize:12.0pt;font-family:&quot;Malgun Gothic&quot;,sans-serif">=EC=9B=94</spa=
n><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-serif"=
> 9</span><span style=3D"font-size:12.0pt;font-family:&quot;Malgun Gothic&q=
uot;,sans-serif">=EC=9D=BC</span><span style=3D"font-size:12.0pt;font-famil=
y:&quot;Arial&quot;,sans-serif"> </span><span style=3D"font-size:12.0pt;fon=
t-family:&quot;Malgun Gothic&quot;,sans-serif">=EC=98=A4=EC=A0=84</span><sp=
an style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-serif"> 7</=
span><span style=3D"font-size:12.0pt;font-family:&quot;Malgun Gothic&quot;,=
sans-serif">=EC=8B=9C</span><span style=3D"font-size:12.0pt;font-family:&qu=
ot;Arial&quot;,sans-serif"> 24</span><span style=3D"font-size:12.0pt;font-f=
amily:&quot;Malgun Gothic&quot;,sans-serif">=EB=B6=84</span><span style=3D"=
font-size:12.0pt;font-family:&quot;Arial&quot;,sans-serif"> 14</span><span =
style=3D"font-size:12.0pt;font-family:&quot;Malgun Gothic&quot;,sans-serif"=
>=EC=B4=88</span><span style=3D"font-size:12.0pt;font-family:&quot;Arial&qu=
ot;,sans-serif"> GMT+09:00, Doug Hardie &lt;<a href=3D"mailto:[email protected]=
g">[email protected]</a>&gt; </span><span style=3D"font-size:12.0pt;font-famil=
y:&quot;Malgun Gothic&quot;,sans-serif">=EC=9E=91=EC=84=B1=ED=95=A8</span><=
span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-serif">:<=
o:p></o:p></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if">&gt; I implemented all that code to load the certificates and keys and =
it worked just fine. However, once I set the keys to 0600, it no longer wor=
ked. The reason is that the startup code that runs as root is quite small. =
It doesn't know which keys will be required. In fact, those keys might not =
even exist yet. They can be added at any time. Hence, the app needs to read=
 the keys after the uid has been changed to the unprivileged uid.<o:p></o:p=
></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if">&gt; <o:p></o:p></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if">&gt; The solution turns out to be changing the setuid to seteuid to the=
 unprivileged user, and then when the connection is starting, in the SSL_CT=
X_set_client_hello_cb routine, use seteuid (0) to go back to root. After th=
e certificate and key are loaded use seteuid to go back to the unprivileged=
 user. This is on FreeBSD. There is a similar, but different implementation=
 for Linux.<o:p></o:p></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if">Not really.&nbsp; It only raises privilege for just enough time to read=
 the certificate and key.&nbsp; That code is checked by me to ensure it doe=
s nothing unusual.<o:p></o:p></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if">-- Doug<o:p></o:p></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if">-- <o:p></o:p></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if">You received this message because you are subscribed to the Google Grou=
ps &quot;openssl-users&quot; group.<o:p></o:p></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if">To unsubscribe from this group and stop receiving emails from it, send =
an email to <a href=3D"mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org">openss=
[email protected]</a>.<o:p></o:p></span></pre>
<pre><span style=3D"font-size:12.0pt;font-family:&quot;Arial&quot;,sans-ser=
if">To view this discussion visit <a href=3D"https://urldefense.com/v3/__ht=
tps:/groups.google.com/a/openssl.org/d/msgid/openssl-users/17570E38-919A-47=
D5-8DA0-53248D5DD490*40sermon-archive.info__;JQ!!FJ-Y8qCqXTj2!cOjW3cavmIqGS=
ZDMJlh9jjTyLtoxc4ayzsyY5HoiOn6iLZp33GZ8kvjRuQfhwYPopJHSNzhFw7gyfh8$">https:=
//urldefense.com/v3/__https://groups.google.com/a/openssl.org/d/msgid/opens=
sl-users/17570E38-919A-47D5-8DA0-53248D5DD490*40sermon-archive.info__;JQ!!F=
J-Y8qCqXTj2!cOjW3cavmIqGSZDMJlh9jjTyLtoxc4ayzsyY5HoiOn6iLZp33GZ8kvjRuQfhwYP=
opJHSNzhFw7gyfh8$</a>.<o:p></o:p></span></pre>
</div>
<i>Any email and files/attachments transmitted with it are intended solely =
for the use of the individual or entity to whom they are addressed. If this=
 message has been sent to you in error, you must not copy, distribute or di=
sclose of the information it contains.
<u>Please notify Entrust immediately and delete the message from your syste=
m.</u></i><br>
<br>
</body>
</html>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;openssl-users&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org">openssl-us=
[email protected]</a>.<br />
To view this discussion visit <a href=3D"https://groups.google.com/a/openss=
l.org/d/msgid/openssl-users/PH3PPF7A88A980A8CEDD2FBE1A2978C33E2F3582%40PH3P=
PF7A88A980A.namprd11.prod.outlook.com?utm_medium=3Demail&utm_source=3Dfoote=
r">https://groups.google.com/a/openssl.org/d/msgid/openssl-users/PH3PPF7A88=
A980A8CEDD2FBE1A2978C33E2F3582%40PH3PPF7A88A980A.namprd11.prod.outlook.com<=
/a>.<br />

--_000_PH3PPF7A88A980A8CEDD2FBE1A2978C33E2F3582PH3PPF7A88A980A_--