[ 
https://issues.apache.org/jira/browse/THRIFT-6078?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Dmytro Shteflyuk closed THRIFT-6078.
------------------------------------
    Fix Version/s: 0.25.0
       Resolution: Fixed

> Ruby SSL clients do not send SNI during TLS handshake
> -----------------------------------------------------
>
>                 Key: THRIFT-6078
>                 URL: https://issues.apache.org/jira/browse/THRIFT-6078
>             Project: Thrift
>          Issue Type: Bug
>          Components: Ruby - Library
>    Affects Versions: 0.23.0
>            Reporter: Dmytro Shteflyuk
>            Assignee: Dmytro Shteflyuk
>            Priority: Major
>             Fix For: 0.25.0
>
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> The Ruby {{Thrift::SSLSocket}} client does not set a TLS server hostname 
> before starting the SSL handshake.
> This can break deployments where a TLS terminator, proxy, or load balancer 
> depends on Server Name Indication (SNI) to route the connection or choose the 
> correct certificate. In those environments the TCP connection can reach the 
> proxy, but the TLS handshake may fail or be routed to the wrong backend 
> because the ClientHello does not include the intended hostname.
> The Ruby client already performs post-handshake hostname verification with 
> {{post_connection_check}}, but that does not help SNI-based routing because 
> the server name must be sent before the handshake completes.
> Expected behavior:
> * Ruby SSL clients should be able to send the intended TLS server hostname 
> during handshake.
> * The default behavior should work for ordinary hostname-based connections.
> * Callers should be able to connect to one address while indicating a 
> different DNS hostname when proxy routing requires it.
> Observed behavior:
> * {{Thrift::SSLSocket}} wraps the TCP socket with {{OpenSSL::SSL::SSLSocket}}.
> * It starts {{connect}} / {{connect_nonblock}} without first setting an 
> OpenSSL hostname.
> * The SNI extension is therefore absent from the client handshake.
> Impact:
> * Ruby Thrift clients may not work behind SNI-aware TLS proxies or 
> multi-tenant TLS endpoints.
> * This differs from several other Thrift clients that pass the logical host 
> into their TLS stack before or during handshake.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to