Recover from failed OCSP download. - #96448

Merged
rzikm merged 2 commits into
dotnet:mainfrom
rzikm:ocsp-staple-fix
Jan 10, 2024
Merged

Recover from failed OCSP download.#96448
rzikm merged 2 commits into
dotnet:mainfrom
rzikm:ocsp-staple-fix

Conversation

@rzikm

@rzikmrzikm commented Jan 3, 2024

Copy link
Copy Markdown
Member

Fixes#96770

When performing OCSP stapling by server and we get invalid response from the OCSP server (either because we don't get any data back or parsing the OCSP response fails), the server will never try to fetch OCSP again because the SslStreamCertificateContext._pendingDownload field still contains the previous task. As a consequence, the server will stop sending OCSP staples after the failure.

This PR moves the _pendingDownload = null assignment to a place where it is guaranteed to execute.

This has a potential pitfall when the given OCSP server is unhealthy (and consistently returning bad response), then we would potentially issue many requests to it. But I understand that if server does not send OCSP staple then clients may fetch the staple themselves, so I am not 100% sure if mitigation from our side changes much. @bartonjs, @vcsjones, what do you think? If we should mitigate it, what mechanism do you suggest? exponential back-off, or maybe even a simple rate-limiting of max 1 request per x minutes?

@ghost

ghost commented Jan 3, 2024

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

When performing OCSP stapling by server and we get invalid response from the OCSP server (either because we don't get any data back or parsing the OCSP response fails), the server will never try to fetch OCSP again because the SslStreamCertificateContext._pendingDownload field still contains the previous task.

This PR moves the _pendingDownload = null assignment to a place where it is guaranteed to execute.

This has a potential pitfall when the given OCSP server is unhealthy (and consistently returning bad response), then we would potentially issue many requests to it. But I understand that if server does not send OCSP staple then clients may fetch the staple themselves, so I am not 100% sure if mitigation from our side changes much. @bartonjs, @vcsjones, what do you think? If we should mitigate it, what mechanism do you suggest? exponential back-off, or maybe even a simple rate-limiting of max 1 request per x minutes?

Author:rzikm
Assignees:-
Labels:

area-System.Net.Security

Milestone:-

@rzikmrzikm added this to the 9.0.0 milestone Jan 3, 2024
@danmoseley

Copy link
Copy Markdown
Contributor

Very naive question - do servers ever request these from other servers, and if so, so they use this code? Just curious whether this is a case where Kestrel may have its own policy.

@rzikm

rzikm commented Jan 4, 2024

Copy link
Copy Markdown
MemberAuthor

Very naive question - do servers ever request these from other servers, and if so, so they use this code? Just curious whether this is a case where Kestrel may have its own policy.

if you mean if this is used in "server-to-server" scenarios, then yes. Technically, the initiator of the connection still acts the role of a client. and the receiver of the connection (the machine acting the server role) will run this code and send an OCSP staple if OCSP stapling was enabled (by SslStreamCertificateContext.Create with right parameters).

Clients are requesting OCSP staple from the server by adding a specific extension to the ClientHello when initiating the connection. Right now, there is no API to control this extension from .NET (not even sure if it is present on all underlying platforms).

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@wfurt

wfurt commented Jan 5, 2024

Copy link
Copy Markdown
Member

BTW do we have test gap? With 5s delay we should be able to craft a test, right?

@rzikm

Copy link
Copy Markdown
MemberAuthor

The testing is not going to be straightforward because most of the code is private. I filed #96791 to track test coverage and will look into it some more once we fix the more urgent issues.

@rzikm
rzikm merged commit a3775a4 into dotnet:mainJan 10, 2024
rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Jan 11, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Jan 11, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
wfurt pushed a commit that referenced this pull request Jan 16, 2024
* Add entire issuer chain to trusted X509_STORE when stapling OCSP_Response (#96792)
* Add entire issuer chain to trusted X509_STORE when validating OCSP_Response
* Code review feedback
* More code review feedback
* Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamCertificateContext.Linux.cs
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
* Fix compilation
* Always include root certificate
---------
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
* Recover from failed OCSP download. (#96448)
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
* Don't shorten OCSP expriation on failed server OCSP fetch (#96972)
* Don't shorten OCSP expriation on failed server OCSP fetch
* Code review feedback
---------
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
rzikm added a commit that referenced this pull request Jan 16, 2024
* Recover from failed OCSP download. (#96448)
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
* Do not OCSP staple invalid OCSP responses
* Add entire issuer chain to trusted X509_STORE when validating OCSP_Response
Code review feedback
More code review feedback
Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamCertificateContext.Linux.cs
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
Fix compilation
Always include root certificate
* Fix compilation
* Don't shorten OCSP expriation on failed server OCSP fetch (#96972)
* Don't shorten OCSP expriation on failed server OCSP fetch
* Code review feedback
---------
Co-authored-by: Kevin Jones <kevin@vcsjones.com>
Co-authored-by: Carlos Sánchez López <1175054+carlossanlop@users.noreply.github.com>
tmds pushed a commit to tmds/runtime that referenced this pull request Jan 23, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Feb 10, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SslStreamCertificateContext stops fetching OCSP staples after one request failure

5 participants

@rzikm@danmoseley@wfurt@stephentoub@bartonjs
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Recover from failed OCSP download. - #96448

Merged
rzikm merged 2 commits into
dotnet:mainfrom
rzikm:ocsp-staple-fix
Jan 10, 2024
Merged

Recover from failed OCSP download.#96448
rzikm merged 2 commits into
dotnet:mainfrom
rzikm:ocsp-staple-fix

Conversation

@rzikm

@rzikmrzikm commented Jan 3, 2024

Copy link
Copy Markdown
Member

Fixes#96770

When performing OCSP stapling by server and we get invalid response from the OCSP server (either because we don't get any data back or parsing the OCSP response fails), the server will never try to fetch OCSP again because the SslStreamCertificateContext._pendingDownload field still contains the previous task. As a consequence, the server will stop sending OCSP staples after the failure.

This PR moves the _pendingDownload = null assignment to a place where it is guaranteed to execute.

This has a potential pitfall when the given OCSP server is unhealthy (and consistently returning bad response), then we would potentially issue many requests to it. But I understand that if server does not send OCSP staple then clients may fetch the staple themselves, so I am not 100% sure if mitigation from our side changes much. @bartonjs, @vcsjones, what do you think? If we should mitigate it, what mechanism do you suggest? exponential back-off, or maybe even a simple rate-limiting of max 1 request per x minutes?

@ghost

ghost commented Jan 3, 2024

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

When performing OCSP stapling by server and we get invalid response from the OCSP server (either because we don't get any data back or parsing the OCSP response fails), the server will never try to fetch OCSP again because the SslStreamCertificateContext._pendingDownload field still contains the previous task.

This PR moves the _pendingDownload = null assignment to a place where it is guaranteed to execute.

This has a potential pitfall when the given OCSP server is unhealthy (and consistently returning bad response), then we would potentially issue many requests to it. But I understand that if server does not send OCSP staple then clients may fetch the staple themselves, so I am not 100% sure if mitigation from our side changes much. @bartonjs, @vcsjones, what do you think? If we should mitigate it, what mechanism do you suggest? exponential back-off, or maybe even a simple rate-limiting of max 1 request per x minutes?

Author:rzikm
Assignees:-
Labels:

area-System.Net.Security

Milestone:-

@rzikmrzikm added this to the 9.0.0 milestone Jan 3, 2024
@danmoseley

Copy link
Copy Markdown
Contributor

Very naive question - do servers ever request these from other servers, and if so, so they use this code? Just curious whether this is a case where Kestrel may have its own policy.

@rzikm

rzikm commented Jan 4, 2024

Copy link
Copy Markdown
MemberAuthor

Very naive question - do servers ever request these from other servers, and if so, so they use this code? Just curious whether this is a case where Kestrel may have its own policy.

if you mean if this is used in "server-to-server" scenarios, then yes. Technically, the initiator of the connection still acts the role of a client. and the receiver of the connection (the machine acting the server role) will run this code and send an OCSP staple if OCSP stapling was enabled (by SslStreamCertificateContext.Create with right parameters).

Clients are requesting OCSP staple from the server by adding a specific extension to the ClientHello when initiating the connection. Right now, there is no API to control this extension from .NET (not even sure if it is present on all underlying platforms).

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@wfurt

wfurt commented Jan 5, 2024

Copy link
Copy Markdown
Member

BTW do we have test gap? With 5s delay we should be able to craft a test, right?

@rzikm

Copy link
Copy Markdown
MemberAuthor

The testing is not going to be straightforward because most of the code is private. I filed #96791 to track test coverage and will look into it some more once we fix the more urgent issues.

@rzikm
rzikm merged commit a3775a4 into dotnet:mainJan 10, 2024
rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Jan 11, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Jan 11, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
wfurt pushed a commit that referenced this pull request Jan 16, 2024
* Add entire issuer chain to trusted X509_STORE when stapling OCSP_Response (#96792)
* Add entire issuer chain to trusted X509_STORE when validating OCSP_Response
* Code review feedback
* More code review feedback
* Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamCertificateContext.Linux.cs
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
* Fix compilation
* Always include root certificate
---------
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
* Recover from failed OCSP download. (#96448)
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
* Don't shorten OCSP expriation on failed server OCSP fetch (#96972)
* Don't shorten OCSP expriation on failed server OCSP fetch
* Code review feedback
---------
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
rzikm added a commit that referenced this pull request Jan 16, 2024
* Recover from failed OCSP download. (#96448)
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
* Do not OCSP staple invalid OCSP responses
* Add entire issuer chain to trusted X509_STORE when validating OCSP_Response
Code review feedback
More code review feedback
Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamCertificateContext.Linux.cs
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
Fix compilation
Always include root certificate
* Fix compilation
* Don't shorten OCSP expriation on failed server OCSP fetch (#96972)
* Don't shorten OCSP expriation on failed server OCSP fetch
* Code review feedback
---------
Co-authored-by: Kevin Jones <kevin@vcsjones.com>
Co-authored-by: Carlos Sánchez López <1175054+carlossanlop@users.noreply.github.com>
tmds pushed a commit to tmds/runtime that referenced this pull request Jan 23, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Feb 10, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SslStreamCertificateContext stops fetching OCSP staples after one request failure

5 participants

@rzikm@danmoseley@wfurt@stephentoub@bartonjs
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Recover from failed OCSP download. - #96448

Merged
rzikm merged 2 commits into
dotnet:mainfrom
rzikm:ocsp-staple-fix
Jan 10, 2024
Merged

Recover from failed OCSP download.#96448
rzikm merged 2 commits into
dotnet:mainfrom
rzikm:ocsp-staple-fix

Conversation

@rzikm

@rzikmrzikm commented Jan 3, 2024

Copy link
Copy Markdown
Member

Fixes#96770

When performing OCSP stapling by server and we get invalid response from the OCSP server (either because we don't get any data back or parsing the OCSP response fails), the server will never try to fetch OCSP again because the SslStreamCertificateContext._pendingDownload field still contains the previous task. As a consequence, the server will stop sending OCSP staples after the failure.

This PR moves the _pendingDownload = null assignment to a place where it is guaranteed to execute.

This has a potential pitfall when the given OCSP server is unhealthy (and consistently returning bad response), then we would potentially issue many requests to it. But I understand that if server does not send OCSP staple then clients may fetch the staple themselves, so I am not 100% sure if mitigation from our side changes much. @bartonjs, @vcsjones, what do you think? If we should mitigate it, what mechanism do you suggest? exponential back-off, or maybe even a simple rate-limiting of max 1 request per x minutes?

@ghost

ghost commented Jan 3, 2024

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

When performing OCSP stapling by server and we get invalid response from the OCSP server (either because we don't get any data back or parsing the OCSP response fails), the server will never try to fetch OCSP again because the SslStreamCertificateContext._pendingDownload field still contains the previous task.

This PR moves the _pendingDownload = null assignment to a place where it is guaranteed to execute.

This has a potential pitfall when the given OCSP server is unhealthy (and consistently returning bad response), then we would potentially issue many requests to it. But I understand that if server does not send OCSP staple then clients may fetch the staple themselves, so I am not 100% sure if mitigation from our side changes much. @bartonjs, @vcsjones, what do you think? If we should mitigate it, what mechanism do you suggest? exponential back-off, or maybe even a simple rate-limiting of max 1 request per x minutes?

Author:rzikm
Assignees:-
Labels:

area-System.Net.Security

Milestone:-

@rzikmrzikm added this to the 9.0.0 milestone Jan 3, 2024
@danmoseley

Copy link
Copy Markdown
Contributor

Very naive question - do servers ever request these from other servers, and if so, so they use this code? Just curious whether this is a case where Kestrel may have its own policy.

@rzikm

rzikm commented Jan 4, 2024

Copy link
Copy Markdown
MemberAuthor

Very naive question - do servers ever request these from other servers, and if so, so they use this code? Just curious whether this is a case where Kestrel may have its own policy.

if you mean if this is used in "server-to-server" scenarios, then yes. Technically, the initiator of the connection still acts the role of a client. and the receiver of the connection (the machine acting the server role) will run this code and send an OCSP staple if OCSP stapling was enabled (by SslStreamCertificateContext.Create with right parameters).

Clients are requesting OCSP staple from the server by adding a specific extension to the ClientHello when initiating the connection. Right now, there is no API to control this extension from .NET (not even sure if it is present on all underlying platforms).

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@wfurt

wfurt commented Jan 5, 2024

Copy link
Copy Markdown
Member

BTW do we have test gap? With 5s delay we should be able to craft a test, right?

@rzikm

Copy link
Copy Markdown
MemberAuthor

The testing is not going to be straightforward because most of the code is private. I filed #96791 to track test coverage and will look into it some more once we fix the more urgent issues.

@rzikm
rzikm merged commit a3775a4 into dotnet:mainJan 10, 2024
rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Jan 11, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Jan 11, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
wfurt pushed a commit that referenced this pull request Jan 16, 2024
* Add entire issuer chain to trusted X509_STORE when stapling OCSP_Response (#96792)
* Add entire issuer chain to trusted X509_STORE when validating OCSP_Response
* Code review feedback
* More code review feedback
* Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamCertificateContext.Linux.cs
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
* Fix compilation
* Always include root certificate
---------
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
* Recover from failed OCSP download. (#96448)
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
* Don't shorten OCSP expriation on failed server OCSP fetch (#96972)
* Don't shorten OCSP expriation on failed server OCSP fetch
* Code review feedback
---------
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
rzikm added a commit that referenced this pull request Jan 16, 2024
* Recover from failed OCSP download. (#96448)
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
* Do not OCSP staple invalid OCSP responses
* Add entire issuer chain to trusted X509_STORE when validating OCSP_Response
Code review feedback
More code review feedback
Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamCertificateContext.Linux.cs
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
Fix compilation
Always include root certificate
* Fix compilation
* Don't shorten OCSP expriation on failed server OCSP fetch (#96972)
* Don't shorten OCSP expriation on failed server OCSP fetch
* Code review feedback
---------
Co-authored-by: Kevin Jones <kevin@vcsjones.com>
Co-authored-by: Carlos Sánchez López <1175054+carlossanlop@users.noreply.github.com>
tmds pushed a commit to tmds/runtime that referenced this pull request Jan 23, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Feb 10, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SslStreamCertificateContext stops fetching OCSP staples after one request failure

5 participants

@rzikm@danmoseley@wfurt@stephentoub@bartonjs
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Recover from failed OCSP download. - #96448

Merged
rzikm merged 2 commits into
dotnet:mainfrom
rzikm:ocsp-staple-fix
Jan 10, 2024
Merged

Recover from failed OCSP download.#96448
rzikm merged 2 commits into
dotnet:mainfrom
rzikm:ocsp-staple-fix

Conversation

@rzikm

@rzikmrzikm commented Jan 3, 2024

Copy link
Copy Markdown
Member

Fixes#96770

When performing OCSP stapling by server and we get invalid response from the OCSP server (either because we don't get any data back or parsing the OCSP response fails), the server will never try to fetch OCSP again because the SslStreamCertificateContext._pendingDownload field still contains the previous task. As a consequence, the server will stop sending OCSP staples after the failure.

This PR moves the _pendingDownload = null assignment to a place where it is guaranteed to execute.

This has a potential pitfall when the given OCSP server is unhealthy (and consistently returning bad response), then we would potentially issue many requests to it. But I understand that if server does not send OCSP staple then clients may fetch the staple themselves, so I am not 100% sure if mitigation from our side changes much. @bartonjs, @vcsjones, what do you think? If we should mitigate it, what mechanism do you suggest? exponential back-off, or maybe even a simple rate-limiting of max 1 request per x minutes?

@ghost

ghost commented Jan 3, 2024

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

When performing OCSP stapling by server and we get invalid response from the OCSP server (either because we don't get any data back or parsing the OCSP response fails), the server will never try to fetch OCSP again because the SslStreamCertificateContext._pendingDownload field still contains the previous task.

This PR moves the _pendingDownload = null assignment to a place where it is guaranteed to execute.

This has a potential pitfall when the given OCSP server is unhealthy (and consistently returning bad response), then we would potentially issue many requests to it. But I understand that if server does not send OCSP staple then clients may fetch the staple themselves, so I am not 100% sure if mitigation from our side changes much. @bartonjs, @vcsjones, what do you think? If we should mitigate it, what mechanism do you suggest? exponential back-off, or maybe even a simple rate-limiting of max 1 request per x minutes?

Author:rzikm
Assignees:-
Labels:

area-System.Net.Security

Milestone:-

@rzikmrzikm added this to the 9.0.0 milestone Jan 3, 2024
@danmoseley

Copy link
Copy Markdown
Contributor

Very naive question - do servers ever request these from other servers, and if so, so they use this code? Just curious whether this is a case where Kestrel may have its own policy.

@rzikm

rzikm commented Jan 4, 2024

Copy link
Copy Markdown
MemberAuthor

Very naive question - do servers ever request these from other servers, and if so, so they use this code? Just curious whether this is a case where Kestrel may have its own policy.

if you mean if this is used in "server-to-server" scenarios, then yes. Technically, the initiator of the connection still acts the role of a client. and the receiver of the connection (the machine acting the server role) will run this code and send an OCSP staple if OCSP stapling was enabled (by SslStreamCertificateContext.Create with right parameters).

Clients are requesting OCSP staple from the server by adding a specific extension to the ClientHello when initiating the connection. Right now, there is no API to control this extension from .NET (not even sure if it is present on all underlying platforms).

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@wfurt

wfurt commented Jan 5, 2024

Copy link
Copy Markdown
Member

BTW do we have test gap? With 5s delay we should be able to craft a test, right?

@rzikm

Copy link
Copy Markdown
MemberAuthor

The testing is not going to be straightforward because most of the code is private. I filed #96791 to track test coverage and will look into it some more once we fix the more urgent issues.

@rzikm
rzikm merged commit a3775a4 into dotnet:mainJan 10, 2024
rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Jan 11, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Jan 11, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
wfurt pushed a commit that referenced this pull request Jan 16, 2024
* Add entire issuer chain to trusted X509_STORE when stapling OCSP_Response (#96792)
* Add entire issuer chain to trusted X509_STORE when validating OCSP_Response
* Code review feedback
* More code review feedback
* Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamCertificateContext.Linux.cs
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
* Fix compilation
* Always include root certificate
---------
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
* Recover from failed OCSP download. (#96448)
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
* Don't shorten OCSP expriation on failed server OCSP fetch (#96972)
* Don't shorten OCSP expriation on failed server OCSP fetch
* Code review feedback
---------
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
rzikm added a commit that referenced this pull request Jan 16, 2024
* Recover from failed OCSP download. (#96448)
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
* Do not OCSP staple invalid OCSP responses
* Add entire issuer chain to trusted X509_STORE when validating OCSP_Response
Code review feedback
More code review feedback
Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamCertificateContext.Linux.cs
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
Fix compilation
Always include root certificate
* Fix compilation
* Don't shorten OCSP expriation on failed server OCSP fetch (#96972)
* Don't shorten OCSP expriation on failed server OCSP fetch
* Code review feedback
---------
Co-authored-by: Kevin Jones <kevin@vcsjones.com>
Co-authored-by: Carlos Sánchez López <1175054+carlossanlop@users.noreply.github.com>
tmds pushed a commit to tmds/runtime that referenced this pull request Jan 23, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Feb 10, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SslStreamCertificateContext stops fetching OCSP staples after one request failure

5 participants

@rzikm@danmoseley@wfurt@stephentoub@bartonjs
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Recover from failed OCSP download. - #96448

Merged
rzikm merged 2 commits into
dotnet:mainfrom
rzikm:ocsp-staple-fix
Jan 10, 2024
Merged

Recover from failed OCSP download.#96448
rzikm merged 2 commits into
dotnet:mainfrom
rzikm:ocsp-staple-fix

Conversation

@rzikm

@rzikmrzikm commented Jan 3, 2024

Copy link
Copy Markdown
Member

Fixes#96770

When performing OCSP stapling by server and we get invalid response from the OCSP server (either because we don't get any data back or parsing the OCSP response fails), the server will never try to fetch OCSP again because the SslStreamCertificateContext._pendingDownload field still contains the previous task. As a consequence, the server will stop sending OCSP staples after the failure.

This PR moves the _pendingDownload = null assignment to a place where it is guaranteed to execute.

This has a potential pitfall when the given OCSP server is unhealthy (and consistently returning bad response), then we would potentially issue many requests to it. But I understand that if server does not send OCSP staple then clients may fetch the staple themselves, so I am not 100% sure if mitigation from our side changes much. @bartonjs, @vcsjones, what do you think? If we should mitigate it, what mechanism do you suggest? exponential back-off, or maybe even a simple rate-limiting of max 1 request per x minutes?

@ghost

ghost commented Jan 3, 2024

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

When performing OCSP stapling by server and we get invalid response from the OCSP server (either because we don't get any data back or parsing the OCSP response fails), the server will never try to fetch OCSP again because the SslStreamCertificateContext._pendingDownload field still contains the previous task.

This PR moves the _pendingDownload = null assignment to a place where it is guaranteed to execute.

This has a potential pitfall when the given OCSP server is unhealthy (and consistently returning bad response), then we would potentially issue many requests to it. But I understand that if server does not send OCSP staple then clients may fetch the staple themselves, so I am not 100% sure if mitigation from our side changes much. @bartonjs, @vcsjones, what do you think? If we should mitigate it, what mechanism do you suggest? exponential back-off, or maybe even a simple rate-limiting of max 1 request per x minutes?

Author:rzikm
Assignees:-
Labels:

area-System.Net.Security

Milestone:-

@rzikmrzikm added this to the 9.0.0 milestone Jan 3, 2024
@danmoseley

Copy link
Copy Markdown
Contributor

Very naive question - do servers ever request these from other servers, and if so, so they use this code? Just curious whether this is a case where Kestrel may have its own policy.

@rzikm

rzikm commented Jan 4, 2024

Copy link
Copy Markdown
MemberAuthor

Very naive question - do servers ever request these from other servers, and if so, so they use this code? Just curious whether this is a case where Kestrel may have its own policy.

if you mean if this is used in "server-to-server" scenarios, then yes. Technically, the initiator of the connection still acts the role of a client. and the receiver of the connection (the machine acting the server role) will run this code and send an OCSP staple if OCSP stapling was enabled (by SslStreamCertificateContext.Create with right parameters).

Clients are requesting OCSP staple from the server by adding a specific extension to the ClientHello when initiating the connection. Right now, there is no API to control this extension from .NET (not even sure if it is present on all underlying platforms).

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@wfurt

wfurt commented Jan 5, 2024

Copy link
Copy Markdown
Member

BTW do we have test gap? With 5s delay we should be able to craft a test, right?

@rzikm

Copy link
Copy Markdown
MemberAuthor

The testing is not going to be straightforward because most of the code is private. I filed #96791 to track test coverage and will look into it some more once we fix the more urgent issues.

@rzikm
rzikm merged commit a3775a4 into dotnet:mainJan 10, 2024
rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Jan 11, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Jan 11, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
wfurt pushed a commit that referenced this pull request Jan 16, 2024
* Add entire issuer chain to trusted X509_STORE when stapling OCSP_Response (#96792)
* Add entire issuer chain to trusted X509_STORE when validating OCSP_Response
* Code review feedback
* More code review feedback
* Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamCertificateContext.Linux.cs
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
* Fix compilation
* Always include root certificate
---------
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
* Recover from failed OCSP download. (#96448)
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
* Don't shorten OCSP expriation on failed server OCSP fetch (#96972)
* Don't shorten OCSP expriation on failed server OCSP fetch
* Code review feedback
---------
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
rzikm added a commit that referenced this pull request Jan 16, 2024
* Recover from failed OCSP download. (#96448)
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
* Do not OCSP staple invalid OCSP responses
* Add entire issuer chain to trusted X509_STORE when validating OCSP_Response
Code review feedback
More code review feedback
Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamCertificateContext.Linux.cs
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
Fix compilation
Always include root certificate
* Fix compilation
* Don't shorten OCSP expriation on failed server OCSP fetch (#96972)
* Don't shorten OCSP expriation on failed server OCSP fetch
* Code review feedback
---------
Co-authored-by: Kevin Jones <kevin@vcsjones.com>
Co-authored-by: Carlos Sánchez López <1175054+carlossanlop@users.noreply.github.com>
tmds pushed a commit to tmds/runtime that referenced this pull request Jan 23, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Feb 10, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SslStreamCertificateContext stops fetching OCSP staples after one request failure

5 participants

@rzikm@danmoseley@wfurt@stephentoub@bartonjs
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Recover from failed OCSP download. - #96448

Merged
rzikm merged 2 commits into
dotnet:mainfrom
rzikm:ocsp-staple-fix
Jan 10, 2024
Merged

Recover from failed OCSP download.#96448
rzikm merged 2 commits into
dotnet:mainfrom
rzikm:ocsp-staple-fix

Conversation

@rzikm

@rzikmrzikm commented Jan 3, 2024

Copy link
Copy Markdown
Member

Fixes#96770

When performing OCSP stapling by server and we get invalid response from the OCSP server (either because we don't get any data back or parsing the OCSP response fails), the server will never try to fetch OCSP again because the SslStreamCertificateContext._pendingDownload field still contains the previous task. As a consequence, the server will stop sending OCSP staples after the failure.

This PR moves the _pendingDownload = null assignment to a place where it is guaranteed to execute.

This has a potential pitfall when the given OCSP server is unhealthy (and consistently returning bad response), then we would potentially issue many requests to it. But I understand that if server does not send OCSP staple then clients may fetch the staple themselves, so I am not 100% sure if mitigation from our side changes much. @bartonjs, @vcsjones, what do you think? If we should mitigate it, what mechanism do you suggest? exponential back-off, or maybe even a simple rate-limiting of max 1 request per x minutes?

@ghost

ghost commented Jan 3, 2024

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

When performing OCSP stapling by server and we get invalid response from the OCSP server (either because we don't get any data back or parsing the OCSP response fails), the server will never try to fetch OCSP again because the SslStreamCertificateContext._pendingDownload field still contains the previous task.

This PR moves the _pendingDownload = null assignment to a place where it is guaranteed to execute.

This has a potential pitfall when the given OCSP server is unhealthy (and consistently returning bad response), then we would potentially issue many requests to it. But I understand that if server does not send OCSP staple then clients may fetch the staple themselves, so I am not 100% sure if mitigation from our side changes much. @bartonjs, @vcsjones, what do you think? If we should mitigate it, what mechanism do you suggest? exponential back-off, or maybe even a simple rate-limiting of max 1 request per x minutes?

Author:rzikm
Assignees:-
Labels:

area-System.Net.Security

Milestone:-

@rzikmrzikm added this to the 9.0.0 milestone Jan 3, 2024
@danmoseley

Copy link
Copy Markdown
Contributor

Very naive question - do servers ever request these from other servers, and if so, so they use this code? Just curious whether this is a case where Kestrel may have its own policy.

@rzikm

rzikm commented Jan 4, 2024

Copy link
Copy Markdown
MemberAuthor

Very naive question - do servers ever request these from other servers, and if so, so they use this code? Just curious whether this is a case where Kestrel may have its own policy.

if you mean if this is used in "server-to-server" scenarios, then yes. Technically, the initiator of the connection still acts the role of a client. and the receiver of the connection (the machine acting the server role) will run this code and send an OCSP staple if OCSP stapling was enabled (by SslStreamCertificateContext.Create with right parameters).

Clients are requesting OCSP staple from the server by adding a specific extension to the ClientHello when initiating the connection. Right now, there is no API to control this extension from .NET (not even sure if it is present on all underlying platforms).

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@wfurt

wfurt commented Jan 5, 2024

Copy link
Copy Markdown
Member

BTW do we have test gap? With 5s delay we should be able to craft a test, right?

@rzikm

Copy link
Copy Markdown
MemberAuthor

The testing is not going to be straightforward because most of the code is private. I filed #96791 to track test coverage and will look into it some more once we fix the more urgent issues.

@rzikm
rzikm merged commit a3775a4 into dotnet:mainJan 10, 2024
rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Jan 11, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Jan 11, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
wfurt pushed a commit that referenced this pull request Jan 16, 2024
* Add entire issuer chain to trusted X509_STORE when stapling OCSP_Response (#96792)
* Add entire issuer chain to trusted X509_STORE when validating OCSP_Response
* Code review feedback
* More code review feedback
* Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamCertificateContext.Linux.cs
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
* Fix compilation
* Always include root certificate
---------
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
* Recover from failed OCSP download. (#96448)
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
* Don't shorten OCSP expriation on failed server OCSP fetch (#96972)
* Don't shorten OCSP expriation on failed server OCSP fetch
* Code review feedback
---------
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
rzikm added a commit that referenced this pull request Jan 16, 2024
* Recover from failed OCSP download. (#96448)
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
* Do not OCSP staple invalid OCSP responses
* Add entire issuer chain to trusted X509_STORE when validating OCSP_Response
Code review feedback
More code review feedback
Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamCertificateContext.Linux.cs
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
Fix compilation
Always include root certificate
* Fix compilation
* Don't shorten OCSP expriation on failed server OCSP fetch (#96972)
* Don't shorten OCSP expriation on failed server OCSP fetch
* Code review feedback
---------
Co-authored-by: Kevin Jones <kevin@vcsjones.com>
Co-authored-by: Carlos Sánchez López <1175054+carlossanlop@users.noreply.github.com>
tmds pushed a commit to tmds/runtime that referenced this pull request Jan 23, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Feb 10, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SslStreamCertificateContext stops fetching OCSP staples after one request failure

5 participants

@rzikm@danmoseley@wfurt@stephentoub@bartonjs
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Recover from failed OCSP download. - #96448

Merged
rzikm merged 2 commits into
dotnet:mainfrom
rzikm:ocsp-staple-fix
Jan 10, 2024
Merged

Recover from failed OCSP download.#96448
rzikm merged 2 commits into
dotnet:mainfrom
rzikm:ocsp-staple-fix

Conversation

@rzikm

@rzikmrzikm commented Jan 3, 2024

Copy link
Copy Markdown
Member

Fixes#96770

When performing OCSP stapling by server and we get invalid response from the OCSP server (either because we don't get any data back or parsing the OCSP response fails), the server will never try to fetch OCSP again because the SslStreamCertificateContext._pendingDownload field still contains the previous task. As a consequence, the server will stop sending OCSP staples after the failure.

This PR moves the _pendingDownload = null assignment to a place where it is guaranteed to execute.

This has a potential pitfall when the given OCSP server is unhealthy (and consistently returning bad response), then we would potentially issue many requests to it. But I understand that if server does not send OCSP staple then clients may fetch the staple themselves, so I am not 100% sure if mitigation from our side changes much. @bartonjs, @vcsjones, what do you think? If we should mitigate it, what mechanism do you suggest? exponential back-off, or maybe even a simple rate-limiting of max 1 request per x minutes?

@ghost

ghost commented Jan 3, 2024

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

When performing OCSP stapling by server and we get invalid response from the OCSP server (either because we don't get any data back or parsing the OCSP response fails), the server will never try to fetch OCSP again because the SslStreamCertificateContext._pendingDownload field still contains the previous task.

This PR moves the _pendingDownload = null assignment to a place where it is guaranteed to execute.

This has a potential pitfall when the given OCSP server is unhealthy (and consistently returning bad response), then we would potentially issue many requests to it. But I understand that if server does not send OCSP staple then clients may fetch the staple themselves, so I am not 100% sure if mitigation from our side changes much. @bartonjs, @vcsjones, what do you think? If we should mitigate it, what mechanism do you suggest? exponential back-off, or maybe even a simple rate-limiting of max 1 request per x minutes?

Author:rzikm
Assignees:-
Labels:

area-System.Net.Security

Milestone:-

@rzikmrzikm added this to the 9.0.0 milestone Jan 3, 2024
@danmoseley

Copy link
Copy Markdown
Contributor

Very naive question - do servers ever request these from other servers, and if so, so they use this code? Just curious whether this is a case where Kestrel may have its own policy.

@rzikm

rzikm commented Jan 4, 2024

Copy link
Copy Markdown
MemberAuthor

Very naive question - do servers ever request these from other servers, and if so, so they use this code? Just curious whether this is a case where Kestrel may have its own policy.

if you mean if this is used in "server-to-server" scenarios, then yes. Technically, the initiator of the connection still acts the role of a client. and the receiver of the connection (the machine acting the server role) will run this code and send an OCSP staple if OCSP stapling was enabled (by SslStreamCertificateContext.Create with right parameters).

Clients are requesting OCSP staple from the server by adding a specific extension to the ClientHello when initiating the connection. Right now, there is no API to control this extension from .NET (not even sure if it is present on all underlying platforms).

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@wfurt

wfurt commented Jan 5, 2024

Copy link
Copy Markdown
Member

BTW do we have test gap? With 5s delay we should be able to craft a test, right?

@rzikm

Copy link
Copy Markdown
MemberAuthor

The testing is not going to be straightforward because most of the code is private. I filed #96791 to track test coverage and will look into it some more once we fix the more urgent issues.

@rzikm
rzikm merged commit a3775a4 into dotnet:mainJan 10, 2024
rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Jan 11, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Jan 11, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
wfurt pushed a commit that referenced this pull request Jan 16, 2024
* Add entire issuer chain to trusted X509_STORE when stapling OCSP_Response (#96792)
* Add entire issuer chain to trusted X509_STORE when validating OCSP_Response
* Code review feedback
* More code review feedback
* Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamCertificateContext.Linux.cs
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
* Fix compilation
* Always include root certificate
---------
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
* Recover from failed OCSP download. (#96448)
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
* Don't shorten OCSP expriation on failed server OCSP fetch (#96972)
* Don't shorten OCSP expriation on failed server OCSP fetch
* Code review feedback
---------
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
rzikm added a commit that referenced this pull request Jan 16, 2024
* Recover from failed OCSP download. (#96448)
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
* Do not OCSP staple invalid OCSP responses
* Add entire issuer chain to trusted X509_STORE when validating OCSP_Response
Code review feedback
More code review feedback
Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamCertificateContext.Linux.cs
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
Fix compilation
Always include root certificate
* Fix compilation
* Don't shorten OCSP expriation on failed server OCSP fetch (#96972)
* Don't shorten OCSP expriation on failed server OCSP fetch
* Code review feedback
---------
Co-authored-by: Kevin Jones <kevin@vcsjones.com>
Co-authored-by: Carlos Sánchez López <1175054+carlossanlop@users.noreply.github.com>
tmds pushed a commit to tmds/runtime that referenced this pull request Jan 23, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Feb 10, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SslStreamCertificateContext stops fetching OCSP staples after one request failure

5 participants

@rzikm@danmoseley@wfurt@stephentoub@bartonjs
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Recover from failed OCSP download. - #96448

Merged
rzikm merged 2 commits into
dotnet:mainfrom
rzikm:ocsp-staple-fix
Jan 10, 2024
Merged

Recover from failed OCSP download.#96448
rzikm merged 2 commits into
dotnet:mainfrom
rzikm:ocsp-staple-fix

Conversation

@rzikm

@rzikmrzikm commented Jan 3, 2024

Copy link
Copy Markdown
Member

Fixes#96770

When performing OCSP stapling by server and we get invalid response from the OCSP server (either because we don't get any data back or parsing the OCSP response fails), the server will never try to fetch OCSP again because the SslStreamCertificateContext._pendingDownload field still contains the previous task. As a consequence, the server will stop sending OCSP staples after the failure.

This PR moves the _pendingDownload = null assignment to a place where it is guaranteed to execute.

This has a potential pitfall when the given OCSP server is unhealthy (and consistently returning bad response), then we would potentially issue many requests to it. But I understand that if server does not send OCSP staple then clients may fetch the staple themselves, so I am not 100% sure if mitigation from our side changes much. @bartonjs, @vcsjones, what do you think? If we should mitigate it, what mechanism do you suggest? exponential back-off, or maybe even a simple rate-limiting of max 1 request per x minutes?

@ghost

ghost commented Jan 3, 2024

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

When performing OCSP stapling by server and we get invalid response from the OCSP server (either because we don't get any data back or parsing the OCSP response fails), the server will never try to fetch OCSP again because the SslStreamCertificateContext._pendingDownload field still contains the previous task.

This PR moves the _pendingDownload = null assignment to a place where it is guaranteed to execute.

This has a potential pitfall when the given OCSP server is unhealthy (and consistently returning bad response), then we would potentially issue many requests to it. But I understand that if server does not send OCSP staple then clients may fetch the staple themselves, so I am not 100% sure if mitigation from our side changes much. @bartonjs, @vcsjones, what do you think? If we should mitigate it, what mechanism do you suggest? exponential back-off, or maybe even a simple rate-limiting of max 1 request per x minutes?

Author:rzikm
Assignees:-
Labels:

area-System.Net.Security

Milestone:-

@rzikmrzikm added this to the 9.0.0 milestone Jan 3, 2024
@danmoseley

Copy link
Copy Markdown
Contributor

Very naive question - do servers ever request these from other servers, and if so, so they use this code? Just curious whether this is a case where Kestrel may have its own policy.

@rzikm

rzikm commented Jan 4, 2024

Copy link
Copy Markdown
MemberAuthor

Very naive question - do servers ever request these from other servers, and if so, so they use this code? Just curious whether this is a case where Kestrel may have its own policy.

if you mean if this is used in "server-to-server" scenarios, then yes. Technically, the initiator of the connection still acts the role of a client. and the receiver of the connection (the machine acting the server role) will run this code and send an OCSP staple if OCSP stapling was enabled (by SslStreamCertificateContext.Create with right parameters).

Clients are requesting OCSP staple from the server by adding a specific extension to the ClientHello when initiating the connection. Right now, there is no API to control this extension from .NET (not even sure if it is present on all underlying platforms).

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@wfurt

wfurt commented Jan 5, 2024

Copy link
Copy Markdown
Member

BTW do we have test gap? With 5s delay we should be able to craft a test, right?

@rzikm

Copy link
Copy Markdown
MemberAuthor

The testing is not going to be straightforward because most of the code is private. I filed #96791 to track test coverage and will look into it some more once we fix the more urgent issues.

@rzikm
rzikm merged commit a3775a4 into dotnet:mainJan 10, 2024
rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Jan 11, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Jan 11, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
wfurt pushed a commit that referenced this pull request Jan 16, 2024
* Add entire issuer chain to trusted X509_STORE when stapling OCSP_Response (#96792)
* Add entire issuer chain to trusted X509_STORE when validating OCSP_Response
* Code review feedback
* More code review feedback
* Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamCertificateContext.Linux.cs
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
* Fix compilation
* Always include root certificate
---------
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
* Recover from failed OCSP download. (#96448)
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
* Don't shorten OCSP expriation on failed server OCSP fetch (#96972)
* Don't shorten OCSP expriation on failed server OCSP fetch
* Code review feedback
---------
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
rzikm added a commit that referenced this pull request Jan 16, 2024
* Recover from failed OCSP download. (#96448)
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
* Do not OCSP staple invalid OCSP responses
* Add entire issuer chain to trusted X509_STORE when validating OCSP_Response
Code review feedback
More code review feedback
Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamCertificateContext.Linux.cs
Co-authored-by: Jeremy Barton <jbarton@microsoft.com>
Fix compilation
Always include root certificate
* Fix compilation
* Don't shorten OCSP expriation on failed server OCSP fetch (#96972)
* Don't shorten OCSP expriation on failed server OCSP fetch
* Code review feedback
---------
Co-authored-by: Kevin Jones <kevin@vcsjones.com>
Co-authored-by: Carlos Sánchez López <1175054+carlossanlop@users.noreply.github.com>
tmds pushed a commit to tmds/runtime that referenced this pull request Jan 23, 2024
* Recover from failed OCSP check.
* Add 5s back-off after failed OCSP querry
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Feb 10, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SslStreamCertificateContext stops fetching OCSP staples after one request failure

5 participants

@rzikm@danmoseley@wfurt@stephentoub@bartonjs