-
Notifications
You must be signed in to change notification settings - Fork 2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Parse CA certificate to catch more specific errors #4340
Conversation
helper/tlsutil/config.go
Outdated
@@ -146,8 +147,18 @@ func (c *Config) AppendCA(pool *x509.CertPool) error { | |||
return fmt.Errorf("Failed to read CA file: %v", err) | |||
} | |||
|
|||
block, _ := pem.Decode([]byte(data)) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The PEM file can have multiple certificates in it. You are only parsing the first. See: https://golang.org/src/crypto/x509/cert_pool.go?s=2791:2855#L102
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Good to know Decode only handles the first, expanding to handle multiple.
Changelog entry as well |
f3635c2
to
8e2da4e
Compare
I'm going to lock this pull request because it has been closed for 120 days ⏳. This helps our maintainers find and focus on the active contributions. |
No description provided.