Re: Cloud integration now works on Switch!
Matan Bareket <[email protected]> Sun, 13 Oct 2019 17:21:38 -0400
| Newsgroups | gmane.games.devel.scummvm |
|---|---|
| Message-ID | <CAJF4eF6e0KndgkTvVxA4vxfdytz=LHp6gr34-Ccw5B1kDiSX7w@mail.gmail.com> |
--===============4805400051276015039== Content-Type: multipart/alternative; boundary="000000000000c258710594d157c2" --000000000000c258710594d157c2 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable There's no problem supplying a copy of the CA cert as part of the package, that's pretty common practice for cross platform applications. Thats the simplest solution On Sun, Oct 13, 2019 at 4:11 PM Alexander Tkachov <[email protected]> wrote: > Hi, > > We had the same problem on Android (still unfixed I believe), so you migh= t > as well fix that on Android then. > > But even though it does work, I doubt that's a proper fix, because you > basically disabled certificate verification. > > I see two ways to "proper fix" that: > > 1. Put certificates file somewhere on user's device and pass the path > to it via CURLOPT_CAINFO option. We can use latest Mozilla's CA that i= s > published here: https://curl.haxx.se/ca/cacert.pem > The "put a file on device" part isn't cool, but we can work with that. > Might be also turned into feature, because user would be able to repla= ce it > with their own certificates, or into vulnerability, if hackers replace= it > with theirs (hackers also would need to control cloud.scummvm.org or > something, so I'd say it's not probable). > 2. Build libcurl with non-OpenSSL backend, so it would have native > cert check (see https://curl.haxx.se/docs/ssl-compared.html). > That's an ideal option, but the problem is that you'd need to port > GnuTLS or something to Android/Switch/whatever and that seems to be he= ll of > a tough thing to do. > > > > Maybe we can have this fix for now, but really intend to "proper fix" it > in the nearest future. Not that users really care about certificate > verification, but that is kinda the right way to do it. > > =E2=80=94 Alexander > > > > 14.10.2019, 02:43, "rsn8887" <[email protected]>: > > Hello all, > I fixed cloud integration on the Nintendo Switch today. It now works as > intended. > > I committed the fix to master branch and cherry-picked it to branch-2-1. > > FWIW, I am voting for a 2.1.1 release. This is a pretty big improvement > IMO, albeit limited to this one platform. > > Cheers, > rsn8887 > -- > rsn8887 [email protected] > Patreon: https://www.patreon.com/rsn8887 > Twitter: https://twitter.com/rsn8887 > Github: https://github.com/rsn8887 > Podcast: https://retrotalk.coolatoms.org > , > > _______________________________________________ > Scummvm-devel mailing list > [email protected] > https://lists.scummvm.org/listinfo/scummvm-devel > > _______________________________________________ > Scummvm-devel mailing list > [email protected] > https://lists.scummvm.org/listinfo/scummvm-devel > --000000000000c258710594d157c2 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">There's no problem supplying a copy of the CA cert as = part of the package, that's pretty common practice for cross platform a= pplications. Thats the simplest solution<br></div><br><div class=3D"gmail_q= uote"><div dir=3D"ltr" class=3D"gmail_attr">On Sun, Oct 13, 2019 at 4:11 PM= Alexander Tkachov <<a href=3D"mailto:[email protected]">alexander@tk= achov.ru</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style=3D= "margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-le= ft:1ex"><div>Hi,</div><div>=C2=A0</div><div>We had the same problem on Andr= oid (still unfixed I believe), so you might as well fix that on Android the= n.</div><div>=C2=A0</div><div>But even though it does work, I doubt that= 9;s a proper fix, because you basically disabled certificate verification.<= br>=C2=A0</div><div><div>I see two ways to "proper fix" that:</di= v><ol><li>Put certificates file somewhere on user's device and pass the= path to it via CURLOPT_CAINFO option. We can use latest Mozilla's CA t= hat is published here: <a href=3D"https://curl.haxx.se/ca/cacert.pem" targe= t=3D"_blank">https://curl.haxx.se/ca/cacert.pem</a><br>The "put a file= on device" part isn't cool, but we can work with that. Might be a= lso turned into feature, because user would be able to replace it with thei= r own certificates, or into vulnerability, if hackers replace it with their= s (hackers also would need to control <a href=3D"http://cloud.scummvm.org" = target=3D"_blank">cloud.scummvm.org</a> or something, so I'd say it'= ;s not probable).</li><li>Build libcurl with non-OpenSSL backend, so it wou= ld have native cert check (see <a href=3D"https://curl.haxx.se/docs/ssl-com= pared.html" target=3D"_blank">https://curl.haxx.se/docs/ssl-compared.html</= a>).<br>That's an ideal option, but the problem is that you'd need = to port GnuTLS or something to Android/Switch/whatever and that seems to be= hell of a tough thing to do.</li></ol></div><ol></ol><div>Maybe we can hav= e this fix for now, but really intend to "proper fix" it in the n= earest future. Not that users really care about certificate verification, b= ut that is kinda the right way to do it.</div><div>=C2=A0</div><div>=E2=80= =94 Alexander</div><div>=C2=A0</div><div>=C2=A0</div><div>=C2=A0</div><div>= 14.10.2019, 02:43, "rsn8887" <<a href=3D"mailto:raist66676@gmx= .de" target=3D"_blank">[email protected]</a>>:</div><blockquote><div sty= le=3D"overflow-wrap: break-word;">Hello all,<div>I fixed cloud integration = on the Nintendo Switch today. It now works as intended.</div><div>=C2=A0</d= iv><div>I committed the fix to master branch and cherry-picked it to branch= -2-1.</div><div>=C2=A0</div><div>FWIW, I am voting for a 2.1.1 release. Thi= s is a pretty big improvement IMO, albeit limited to this one platform.</di= v><div>=C2=A0</div><div>Cheers,</div><div>rsn8887</div><div>--</div><div><d= iv><div style=3D"color:rgb(0,0,0);text-decoration:none;text-indent:0px;text= -transform:none;white-space:normal;word-spacing:0px"><div style=3D"color:rg= b(0,0,0);text-decoration:none;text-indent:0px;text-transform:none;white-spa= ce:normal;word-spacing:0px"><div>rsn8887 <a href=3D"mailto:[email protected]= e" target=3D"_blank">[email protected]</a></div><div>Patreon:=C2=A0<a href= =3D"https://www.patreon.com/rsn8887" target=3D"_blank">https://www.patreon.= com/rsn8887</a></div><div>Twitter:=C2=A0<a href=3D"https://twitter.com/rsn8= 887" target=3D"_blank">https://twitter.com/rsn8887</a><br>Github:=C2=A0<a h= ref=3D"https://github.com/rsn8887" target=3D"_blank">https://github.com/rsn= 8887</a><br>Podcast:=C2=A0<a href=3D"https://retrotalk.coolatoms.org/" targ= et=3D"_blank">https://retrotalk.coolatoms.org</a></div></div></div></div></= div></div>,<p>_______________________________________________<br>Scummvm-de= vel mailing list<br><a href=3D"mailto:[email protected]" targ= et=3D"_blank">[email protected]</a><br><a href=3D"https://lis= ts.scummvm.org/listinfo/scummvm-devel" target=3D"_blank">https://lists.scum= mvm.org/listinfo/scummvm-devel</a></p></blockquote>________________________= _______________________<br> Scummvm-devel mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank">Scummv= [email protected]</a><br> <a href=3D"https://lists.scummvm.org/listinfo/scummvm-devel" rel=3D"norefer= rer" target=3D"_blank">https://lists.scummvm.org/listinfo/scummvm-devel</a>= <br> </blockquote></div> --000000000000c258710594d157c2-- --===============4805400051276015039== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Scummvm-devel mailing list [email protected] https://lists.scummvm.org/listinfo/scummvm-devel --===============4805400051276015039==--