Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

TLS certificate includes blank X509v3 Subject Alternative Name #2664

Closed
4 tasks
NodeGuy opened this issue Nov 2, 2018 · 1 comment
Closed
4 tasks

TLS certificate includes blank X509v3 Subject Alternative Name #2664

NodeGuy opened this issue Nov 2, 2018 · 1 comment
Assignees
Labels

Comments

@NodeGuy
Copy link
Contributor

NodeGuy commented Nov 2, 2018

Summary of Bug

The X509v3 Subject Alternative Name DNS field in the TLS certificate is blank, causing an error in a client when it attempts to connect to the REST server.

Steps to Reproduce

$ gaiacli version
0.24.2-839-gce23ad41
$ gaiacli rest-server --trust-node=true
I[11-01|23:02:30.801] Starting RPC HTTPS server on tcp://localhost:1317 (cert: "/var/folders/wj/0h36fvtj03q0y9lf0n9c0nxc0000gp/T/cert_209481810", key: "/var/folders/wj/0h36fvtj03q0y9lf0n9c0nxc0000gp/T/key_803768713") module=rest-server

In another console:

$ openssl x509 -in /var/folders/wj/0h36fvtj03q0y9lf0n9c0nxc0000gp/T/cert_209481810 -text -noout
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            fd:4e:45:2e:bc:9e:6e:1b:8f:22:42:74:bb:83:a2:7a
    Signature Algorithm: ecdsa-with-SHA256
        Issuer: O=Gaia Lite
        Validity
            Not Before: Nov  2 03:02:30 2018 GMT
            Not After : Dec  2 03:02:30 2018 GMT
        Subject: O=Gaia Lite
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (256 bit)
                pub: 
                    04:48:78:b2:ed:ee:f9:19:13:6b:9b:00:57:34:ab:
                    88:35:41:f1:3c:ec:56:a8:08:c6:74:2f:8b:9f:5a:
                    fd:9c:db:9d:17:27:60:38:d0:06:79:86:58:e8:5b:
                    6b:d3:81:0d:0a:dd:13:1d:3d:ef:88:89:b5:81:8c:
                    5f:d9:47:42:69
                ASN1 OID: prime256v1
                NIST CURVE: P-256
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Key Encipherment, Certificate Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Subject Alternative Name: 
                DNS:
    Signature Algorithm: ecdsa-with-SHA256
         30:45:02:21:00:ea:14:92:a2:b0:57:2d:57:72:14:6b:a6:07:
         c0:4e:2d:48:18:08:73:a0:fe:44:a3:2d:10:6c:da:33:fb:45:
         6e:02:20:56:4c:af:d1:76:4c:e2:3c:d2:fc:ec:97:eb:e4:2e:
         7d:5e:cb:34:23:24:f5:59:d4:be:9b:cd:24:cc:cc:81:72

$ curl --cacert /var/folders/wj/0h36fvtj03q0y9lf0n9c0nxc0000gp/T/cert_209481810 https://localhost:1317/node_version
curl: (51) SSL: no alternative certificate subject name matches target host name 'localhost'

For Admin Use

  • Not duplicate issue
  • Appropriate labels applied
  • Appropriate contributors tagged
  • Contributor assigned/self-assigned
@alessio
Copy link
Contributor

alessio commented Nov 2, 2018

This should work I guess:

$ openssl x509 -in /tmp/cert_546561472 -text -noout
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            3f:77:d7:fa:36:a3:df:9a:fe:0b:03:33:5a:e6:a2:82
    Signature Algorithm: ecdsa-with-SHA256
        Issuer: O = Gaia Lite
        Validity
            Not Before: Nov  2 08:16:23 2018 GMT
            Not After : Dec  2 08:16:23 2018 GMT
        Subject: O = Gaia Lite
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (256 bit)
                pub:
                    04:d7:81:b6:0e:c9:f6:c8:27:ee:d6:52:c9:74:e2:
                    f8:58:db:ea:99:17:50:c1:c8:fc:44:67:3a:62:36:
                    12:64:6e:28:21:5b:96:0a:42:f2:07:6e:68:17:d0:
                    bc:ca:f8:4d:df:01:c7:86:b8:ab:a1:9e:a5:9f:f4:
                    46:21:6a:d6:98
                ASN1 OID: prime256v1
                NIST CURVE: P-256
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Key Encipherment, Certificate Sign
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Subject Alternative Name: 
                DNS:localhost, DNS:
    Signature Algorithm: ecdsa-with-SHA256
         30:45:02:20:73:26:3c:e8:7a:aa:ba:1d:52:32:c5:35:de:f7:
         9f:0a:b9:5b:10:66:b9:84:8b:86:d6:15:5c:f4:83:32:99:c5:
         02:21:00:be:6e:d9:39:a9:d6:57:e2:39:ca:9a:c4:65:4a:4e:
         d8:72:4d:99:92:c1:94:fe:3e:d9:cd:e3:20:20:5c:0e:62

alessio pushed a commit that referenced this issue Nov 2, 2018
@alessio alessio self-assigned this Nov 2, 2018
@alessio alessio added the lite label Nov 2, 2018
MarcelMWS added a commit to MarcelMWS/cosmos-sdk that referenced this issue Nov 15, 2018
* Back to 50 initially bonded

* Add query deposits cmds

* Update test

* Update PENDING.md

* Back to on-operation=false, update PENDING.md

* Remove unnecessary change, clarify amt in sim_test.go

* Cleanup, additional item in PENDING.md

* Update PENDING.md

Co-Authored-By: alessio <[email protected]>

* Update client/keys/utils.go

Co-Authored-By: alessio <[email protected]>

* update depositer addr

* Address @rigelrozanski comments

* Make linter happy

* Update PENDING.md

* Remove shorthand

* Make "multi" const

* Store last total power as sdk.Int, not sdk.Dec

* Merge PR cosmos#2553: Renamed msg.Name() and msg.Type() to msg.Type() and msg.Route()

* Fix stupid mistake

* s/number/weight/

* LastValidatorPower is also an Int

* Merge PR cosmos#2462: Add swagger-ui for gov, stake and slashing

* 'make format'

* Move PENDING to CHANGELOG

* Linkify changelog

* Fix db write perm

* Additional cleanup

* Remove logs from prior debugging

* Merge PR cosmos#2599 from cosmos/jae/dist_refactor

* Rename Pool -> DelRewards; PoolCommission -> ValCommision
* FeePool.Pool -> FeePool.ValPool
* WithdrawalHeight->DelPoolWithdrawalHeight
* OnValidatorBeginUnbonding
* Caught the bug's tail
* Update vi.FeePoolWithdrawalHeight upon bonding
* Fix staking slashUnbondingDelegation bug; fixes simulator failure cosmos#9

* Merge PR cosmos#2597: Add distribution accum invariants

* PENDING.md => CHANGELOG.md

* Manually linkify

* Manually fix some links

* Docs fixes in progress while running through the release process

* More docs fixes

* '--voter' is no longer required

* Rectify validator setup documentation

* Merge PR cosmos#2596: Cmds for validator unbondings and redelegations

* Make simulation use a transition matrix for block size

This enables simulating periods of high load, and periods of low to no load.
(low load because future ops will still terminate in that time frame)

* address bez's comments

* fix flags in docs, closes cosmos#2530

* Merge PR cosmos#2616: Block redelegations to the same validator

* Merge PR cosmos#2623: Speedup simulator by switching to goleveldb

Due to requiring app.Commit() at the moment, golevel db is significantly faster than a memdb

* fix block offsets in printing simulation block number

* Merge PR cosmos#2644: Simulation: Print last block when there is an error

There was an off by one error in the log printing function previously

* Merge PR cosmos#2642: Add todo diagrams

* Various sign command improvements

- Exit with error if the user is attempting to sign with a key
  whose address is not among those who are expected to sign
  the transaction.

- Add --print-signature-only to output only the generated
  signature.

* Check sanity of signatures and report errors when run with --print-sigs

* Improve errors reporting

* Improve online docs

* Refresh PENDING.md

* Find better name for --print-signature-only

* Fix integration tests

* Validate --name

* Fix integration tests

* s/--print-sigs/--validate-signatures/

* s/--sig-only/--signature-only/

* Docs updated

* Update PENDING.md

* Rename append, it's go builtin

* Set success = false when it fails

* Apply suggestions from bez

* Nest switches

* Fix rebase

* Document what --validate-signatures does

* perform minor doc and function cleanup

* move typedef

* Merge PR cosmos#2614: Configurable Bech32 prefix for SDK users

* Merge PR cosmos#2643: AppendTag function usage error. append elements do not work

* simulation: Make validator choice use validator set

This also had to change the default seed, since with the previous one it
actually got into a state where there were no validators left bonded, lol.

This also changes Unbond msgs from failing with almost 100% probability to now
only failing with 33% probability.
Thus more of the state machine is getting tested!

* Update changelog

* Merge PR cosmos#2657: Fix config.js

* Merge PR cosmos#2589: Update Vesting Spec

* Merge PR cosmos#2656: Revert read-only leveldb database

* Revert read-only leveldb database

Waiting on a fix for syndtr/goleveldb#240.

* Update client/keys/utils.go

* Include DNS alt name in certificate

Closes: cosmos#2664

* Gaialite signal handling is broken, repair it

* Merge PR cosmos#2665: simulation: Remove header from Invariant

This got introduced recently, but wasn't actually needed, hence the reversion

* Merge PR cosmos#2653: Add benchmark for get and set account

* Fix test

* Refactor TrapSignal

* Fix lint

* enforcing @jaekwon mergemaster

* added querier redelegation

* added validatorDelegations querier endpoint

* LCD and CLI

* cli fixes

* removed redelegation stuff

* address other comments

* rebased

* addressed comments

* Make the simulator create the new comission rate sensibly

* Update to TM v0.26.0 - Part I (cosmos#2679)

* Update to TM v0.26.0

* Bez/tm0.26 update pt 2 redux (cosmos#2684)

* Update to TM v0.26.0
* Update TODOs
* Proof and verification updates
* Fix linting
* Fix key path creation
* Temporarily fix tendermint revision to make tests pass

* Fix merge conflict bug; Update PENDING

* New genesis workflow (cosmos#2602)

New genesis workflow:
* `gaiad init` is now used to generate an empty `genesis.json`.
* Genesis accounts need to be populated manually before running
  `gaiad collect-gentxs`.
* This should support starfish too, see cosmos#2615 for more info.
* Closes: cosmos#2596 cosmos#2615
* Validate validator address and address against respective account ex ante
* Fix local testnet failures
* New genesis tests
* Run make format
* Add --pubkey flag
* gaiad collect-gentxs takes no args

* Simulation improvements (logging fix, random genesis parameters) (cosmos#2617)

* Print out initial update on every block
* Randomize simulation parameters
* Randomize initial liveness weightings
* Randomize genesis parameters
* fixed power store invariant
* IterateValidatorsBonded -> IterateBondedValidatorsByPower
* WriteValidators uses IterateLastValidators rather than IterateBondedValidatorsByPower
* fixed democoin interface

Closes cosmos#2556
Closes cosmos#2396

Via cosmos#2671:
closes cosmos#2669
closes cosmos#2670
closes cosmos#2620

Offshoot issues:
cosmos#2618
cosmos#2619
cosmos#2620
cosmos#2661

* Fix simulation bugs; Incorprates cosmos#2676 from Sunny (cosmos#2677)

* Fix simulation bugs; Incorprates cosmos#2676 from Sunny
* Address review feedback; Update PENDING

* 'make format'

* Revert "enforcing @jaekwon mergemaster"

This reverts commit 15c2093.

* Update x/stake/client/rest/query.go

Co-Authored-By: sunnya97 <[email protected]>

* addressed fede's comment

* Switch gov proposal-queues to use iterators (cosmos#2638)

* switched gov proposals queue to use iterators
* update gov spec
* update proposal.Equal
* Amino api change
* switched proposalID to uint64
* renamed Gov Procedures to Params
* s/ActiveProposalQueueProposalKey/KeyActiveProposalQueueProposal/g
* numLatestProposals -> Limit
* fixed staking invariant breakage because of gov deposits
* Send deposits to DepositedCoinsAccAddr or BurnedDepositCoinsAccAddr

* Add general merkle absence proof (also for empty substores) (cosmos#2685)

* Fix coins.IsLT() impl (cosmos#2686)

* Fix coins.IsLT() impl
* Fix coin.IsLT() impl
* Coins.IsLT -> Coins.IsAllLT etc

* Update testnet to use canonical genesis time (cosmos#2692)

* Update testnet to use canonical genesis time
* Fix linting in genesis test

* Do not allow nil values to be set in CacheKVStore (cosmos#2708)

* Do not allow nil values to be set in CacheKVStore

* Makefile OS compatibility update

* Merge PR cosmos#2714: Add commission data to MsgCreateValidator signature bytes

* PENDING => CHANGELOG

* Linkify changelog

* Cleanup bank keeper

* whitespacing

* rand utile

...

* moving stuff around a bit, trying to get rid of types

* reorganize more

* rename ambig naming of queueOperations

* minimizing indentation

* fix some duplicate to get passing

* Address style comments

* Reorganize CLI command structure. Fixes cosmos#2575

* Fix missing flags issue

* Address linting issues

* Fix gobash CLI testing

* Fix typo

* Cross-compiling get_tools Makefile added

* operations functions

* assertAllInvarients changes, Operation reorg

* mock tendermint

* util cleanup

* event stats object, more general cleanup

* compiling

* pending

* Removed comment from Makefile as per bez's request

* val comments

* Address PR comments

* Update cmd/gaia/cmd/gaiacli/main.go

Co-Authored-By: jackzampolin <[email protected]>

* PENDING

* Fix state export/import, add to CI (cosmos#2690)

* Update slashing import/export
* More slashing.WriteGenesis
* Add test import/export to CI
* Store equality comparison.
* Fix validator bond intra-tx counter
* Set timeslices for unbonding validators
* WriteGenesis => ExportGenesis
* Delete validators from unbonding queue when re-bonded
* Hook for validator deletion, fix staking genesis tests

* Merge 0.26.0 back to develop (cosmos#2718)

* PENDING => CHANGELOG
* Linkify changelog
* Merge PR cosmos#2716: Temporarily disable gaia lite insecure mode
* TODO: need to update CHANGELOG w/ import-export PR cosmos#2690

* Update CHANGELOG/PENDING for straggling PR cosmos#2690

* Add small utility to add account to genesis.json after gaiad init

* Update CHANGELOG.md

* s/WriteGenesisFile/ExportGenesisFile/

* Update PENDING.md

* Add --chain-id to testnet command

* Address remaining comments from cosmos#2690

* Update PENDING.md

* add back in PeriodicInvariant

* Linter fix

* Fix TimeoutCommit (cosmos#2743)

* Fix TimeoutCommit to 5 seconds instead of whatever it was before which was too short.

* Gaia-9000: Update to TM 0.26.1-rc2 (cosmos#2753)

* Update to tm 0.26.1-rc2 to fix prometheus issue and node disconnect issue.

* Gaia-9000: Update to TM 0.26.1-rc3 -- pex SeedMode fix

* fix typo

I think it might be a spelling mistake

* Slight distribution spec cleanup

* More cleanup

* use defer

* Use correct Bech32 prefix for show-address command (cosmos#2746)

* Use consensus address bech32 prefix
* Update show-address CLI description

* Generate random moniker when missing

* Update moniker prefix

* Require moniker instead of generating a random one

* update to tendermint v0.26.1

* Fix test coverage

* Correctly set return code

* Fix date to be cross platform

* Merge PR cosmos#2752: Don't hardcode bondable denom

* R4R: Fix unbonding command flow (cosmos#2727)

* Fix required flag

* Fix redelegation command

* Add pending entry

* update swagger.yaml

* use newQuery...Params

* Link to issue

* Fix DiffKVStore

* Address PR review

* Working on stake import/export

* Only apply validator set updates on initial genesis

* Clarify comment

* Fix failing test

* add back in CLI command after rebase

* Fix CLI tests

* update to amino 0.14.1

* pending

* R4R:  Query Gov Params (cosmos#2576)

* gov query params

* Merge PR cosmos#2744: Fix Makefile targets dependencies

* Fix Makefile targets dependencies
* Remove unnecessary build deps from install targets
* Create a rule for each tool
* Don't dep test_lint on tools

* Update docs/spec/distribution/overview.md

Co-Authored-By: alexanderbez <[email protected]>

* Update docs/spec/distribution/overview.md

Co-Authored-By: alexanderbez <[email protected]>

* Update docs/spec/distribution/overview.md

Co-Authored-By: alexanderbez <[email protected]>

* Update overview.md

* Documentation Structure Change and Cleanup (cosmos#2808)

* Update docs/sdk/clients.md
* organize ADR directory like tendermint
* docs: move spec-proposals into spec/
* remove lotion, moved to website repo
* move getting-started to cosmos-hub, and voyager to website
* docs: move lite/ into clients/lite/
* move introduction/ content to website repo
* move resources/ content to website repo
* mv sdk/clients.md to clients/clients.md
* mv validators to cosmos-hub/validators
* move deprecated sdk/ content to _attic
* sdk/modules.md is duplicate with modules/README.md
* consolidate remianing sdk/ files into a single sdk.md
* move examples/ to docs/examples/
* mv docs/cosmos-hub to docs/gaia
* Add keys/accounts section to localnet docs

* Bring back banner (cosmos#2814)

* Build docs in CircleCI  (cosmos#2810)

* error checking the API call
* added docs build trigger to circleci job

* Update contributing.md with new merge policy (cosmos#2789)

* Update contribuiting.md with new merge policy

* deleted obsolete file (cosmos#2817)
fedekunze pushed a commit to luniehq/lunie that referenced this issue Nov 17, 2018
* change init local testnet to latest SDK

* working initialising

* WIP: Implement HTTPS support for Gaia Lite.

Blocked by cosmos/cosmos-sdk#2664

* using working commit

* updated to latest

* working node start

* working https

* remove decimals fix

* fixed some tests related to updating

* correctly map unbonding delegations and txs

* pipe init

* clear all data on overwrite

* go to 0.26-rc0

* Fix a bunch of tests in lcdClient.spec.

* most tests fixed

* fixed last test in main

* tests all passing

* working e2e test start

* declaring validators works

* all e2e tests passed

* comments

* linted

* refactor

* refactors

* reverted to axios proxy

* fixed refactor issues

* fixed refactor issues

* linted

* skip using url for communicating lcdPort

* removed ratTo when not needed

* added catching

* added logging

* fix ubuntu running

* fixed e2e test (passing wrong dir to tests)

* fixed coverage issues in lcdclient

* added test for axios proxy

* Update app/src/renderer/connectors/lcdClient.js

Co-Authored-By: faboweb <[email protected]>

* Update tasks/gaia.js

Co-Authored-By: faboweb <[email protected]>

* Update test/e2e/launch.js

Co-Authored-By: faboweb <[email protected]>

* implemented comments

* fixed test

* Update lcdClient.js
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants