Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1186406 > unrolled thread

Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled

Started byManfred Stock <m-debian@nfred.ch>
First post2024-02-16 16:10 +0100
Last post2024-03-03 16:30 +0100
Articles 5 — 2 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled Manfred Stock <m-debian@nfred.ch> - 2024-02-16 16:10 +0100
    Bug#1050336: Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled gregor herrmann <gregoa@debian.org> - 2024-02-18 01:50 +0100
      Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled Manfred Stock <m-debian@nfred.ch> - 2024-02-19 21:10 +0100
        Bug#1032868: Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled gregor herrmann <gregoa@debian.org> - 2024-02-21 21:00 +0100
      Bug#1064058: Bug#1050336: Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled gregor herrmann <gregoa@debian.org> - 2024-03-03 16:30 +0100

#1186406 — Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled

FromManfred Stock <m-debian@nfred.ch>
Date2024-02-16 16:10 +0100
SubjectBug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled
Message-ID<I880F-ayDC-17@gated-at.bofh.it>
Package: libxml-stream-perl
Version: 1.24-4
Severity: normal
Tags: upstream
Control: affects -1 sendxmpp libnet-xmpp-perl

Dear Maintainers,

after upgrading to Debian Bookworm, we noticed that the sendxmpp command
line tool was not working anymore in our setup. During the investigation
of this issue, I noticed that downgrading IO-Socket-SSL to the version
in Bullseye made sendxmpp work again. I then started to try all versions
of IO-Socket-SSL between the version in Bullseye and the one in Bookworm
and found that it stopped working with version 2.078. Eventually, I came
up with a pull request [1] containing a patch that fixed it for us -
apparently, the way XML-Stream was using IO-Socket-SSL most likely
always resulted in the hostname verification to be done against the IP
address of the peer instead of an actual hostname, which was always
considered to be successful in IO-Socket-SSL < 2.078, but not anymore in
newer versions.

Since the upstream seems quite inactive, it might be worth considering
to add this or a similar patch to the package in Debian, as I came
across several other bug reports in the Debian BTS which might actually
be caused by this issue, like #986971 [2], #1032868 [3] and maybe also
#1050336 [4] - at least the error messages in the first two look very
similar to what I saw.

Cheers,
Manfred

[1]: https://github.com/dap/XML-Stream/pull/28
[2]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=986971
[3]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1032868
[4]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1050336

-- System Information:
Debian Release: 12.5
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 6.1.0-18-amd64 (SMP w/4 CPU threads; PREEMPT)
Kernel taint flags: TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE
Locale: LANG=de_CH.utf8, LC_CTYPE=de_CH.utf8 (charmap=UTF-8), LANGUAGE=de_CH:de
Shell: /bin/sh linked to /usr/bin/dash
Init: unable to detect

Versions of packages libxml-stream-perl depends on:
ii  libauthen-sasl-perl    2.1600-3
ii  libio-socket-ssl-perl  2.081-2
ii  perl                   5.36.0-7+deb12u1

libxml-stream-perl recommends no packages.

Versions of packages libxml-stream-perl suggests:
ii  libnet-dns-perl  1.36-1

-- no debconf information

[toc] | [next] | [standalone]


#1186564 — Bug#1050336: Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled

Fromgregor herrmann <gregoa@debian.org>
Date2024-02-18 01:50 +0100
SubjectBug#1050336: Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled
Message-ID<I8Dxy-aRz3-59@gated-at.bofh.it>
In reply to#1186406

[Multipart message — attachments visible in raw view] — view raw

On Fri, 16 Feb 2024 15:56:04 +0100, Manfred Stock wrote:

> after upgrading to Debian Bookworm, we noticed that the sendxmpp command
> line tool was not working anymore in our setup. During the investigation
> of this issue, I noticed that downgrading IO-Socket-SSL to the version
> in Bullseye made sendxmpp work again. I then started to try all versions
> of IO-Socket-SSL between the version in Bullseye and the one in Bookworm
> and found that it stopped working with version 2.078. Eventually, I came
> up with a pull request [1] containing a patch that fixed it for us -
> apparently, the way XML-Stream was using IO-Socket-SSL most likely
> always resulted in the hostname verification to be done against the IP
> address of the peer instead of an actual hostname, which was always
> considered to be successful in IO-Socket-SSL < 2.078, but not anymore in
> newer versions.

Oh wow -- thank you!

I remember looking at #1050336 in libnet-xmpp-perl and having the
suspicion that the problem is actually in libxml-stream-perl, but
never managed to nail it down.
 
> Since the upstream seems quite inactive, it might be worth considering
> to add this or a similar patch to the package in Debian, as I came
> across several other bug reports in the Debian BTS which might actually
> be caused by this issue, like #986971 [2], #1032868 [3] and maybe also
> #1050336 [4] - at least the error messages in the first two look very
> similar to what I saw.

I've uploaded libxml-stream-perl 1.24-5 to unstable right now.

I'd like to invite the submitters of the other bugs to tests if there
problems are fixed with libxml-stream-perl 1.24-5.

If yes, I'm happy to
- do some BTS manipulation
- more relevant: get this fix into bookworm for the next point
  release.
 

Thanks again,
gregor

-- 
 .''`.  https://info.comodo.priv.at -- Debian Developer https://www.debian.org
 : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D  85FA BB3A 6801 8649 AA06
 `. `'  Member VIBE!AT & SPI Inc. -- Supporter Free Software Foundation Europe
   `-   

[toc] | [prev] | [next] | [standalone]


#1186747

FromManfred Stock <m-debian@nfred.ch>
Date2024-02-19 21:10 +0100
Message-ID<I9i7D-bgzN-1@gated-at.bofh.it>
In reply to#1186564
Hi gregor,

Am Sun, Feb 18, 2024 at 01:41:20AM +0100 schrieb gregor herrmann:
> On Fri, 16 Feb 2024 15:56:04 +0100, Manfred Stock wrote:
>
> > after upgrading to Debian Bookworm, we noticed that the sendxmpp command
> > line tool was not working anymore in our setup. [...] Eventually, I came
> > up with a pull request [1] containing a patch that fixed it for us -
> > [...]
>
> Oh wow -- thank you!

you're welcome, and thanks for your quick response!


> I remember looking at #1050336 in libnet-xmpp-perl and having the
> suspicion that the problem is actually in libxml-stream-perl, but
> never managed to nail it down.

It actually took me a while, too ;). I think I ended up in XML-Stream
because of the debug output, especially the binary part that was printed
in the output of a read operation. A few detours later, I found the
IO-Socket-SSL release where it stopped working and remembered that
start_SSL() was called in XML::Stream and that an example in the
documentation somewhere passed a hostname, which wasn't done in
XML::Stream. In conclusion, the error handling in XML::Stream (and maybe
Net::XMPP as well) seems to have some room for improvement, and I also
noticed that some messages in the debug output are quite misleading (the
"We are secure", for example, that was printed in TLSClientProceed(),
simply wasn't correct, at this point, upgrading the socket to SSL/TLS
had failed).


> > Since the upstream seems quite inactive, it might be worth considering
> > to add this or a similar patch to the package in Debian, as I came
> > across several other bug reports in the Debian BTS which might actually
> > be caused by this issue, like #986971 [2], #1032868 [3] and maybe also
> > #1050336 [4] - at least the error messages in the first two look very
> > similar to what I saw.
>
> I've uploaded libxml-stream-perl 1.24-5 to unstable right now.

Thanks! I quickly tested this package and can confirm that it works for
me.


> I'd like to invite the submitters of the other bugs to tests if there
> problems are fixed with libxml-stream-perl 1.24-5.
>
> If yes, I'm happy to
> - do some BTS manipulation
> - more relevant: get this fix into bookworm for the next point
>   release.

This would be great, thanks!


Cheers,
Manfred

[toc] | [prev] | [next] | [standalone]


#1186966 — Bug#1032868: Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled

Fromgregor herrmann <gregoa@debian.org>
Date2024-02-21 21:00 +0100
SubjectBug#1032868: Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled
Message-ID<Ia0V3-bHrL-3@gated-at.bofh.it>
In reply to#1186747

[Multipart message — attachments visible in raw view] — view raw

Control: reassign 1032868 libxml-stream-perl 1.24-4
Control: reassign 1050336 libxml-stream-perl 1.24-4
Control: fixed 1032868 1.24-5
Control: fixed 1050336 1.24-5
Control: tag 986971 bookworm sid trixie upstream
Control: tag 1032868 bookworm sid trixie upstream
Control: tag 1050336 bookworm sid trixie upstream


On Mon, 19 Feb 2024 20:48:26 +0100, Manfred Stock wrote:

> > I remember looking at #1050336 in libnet-xmpp-perl and having the
> > suspicion that the problem is actually in libxml-stream-perl, but
> > never managed to nail it down.
> It actually took me a while, too ;). 

Heh :)

> I think I ended up in XML-Stream
> because of the debug output, especially the binary part that was printed
> in the output of a read operation. A few detours later, I found the
> IO-Socket-SSL release where it stopped working and remembered that
> start_SSL() was called in XML::Stream and that an example in the
> documentation somewhere passed a hostname, which wasn't done in
> XML::Stream. 

And that was the nice finding.

> > I've uploaded libxml-stream-perl 1.24-5 to unstable right now.
> Thanks! I quickly tested this package and can confirm that it works for
> me.

Great, thanks.
 
> 
> > I'd like to invite the submitters of the other bugs to tests if there
> > problems are fixed with libxml-stream-perl 1.24-5.
> >
> > If yes, I'm happy to
> > - do some BTS manipulation
> > - more relevant: get this fix into bookworm for the next point
> >   release.
> 
> This would be great, thanks!

In #986971 Martin has already confirmed that libxml-stream-perl/1.24-5
fixes his issue, and the bug has been reassigned. I'm now reassigning
the other 2 bugs and will merge them later.


Cheers,
gregor

-- 
 .''`.  https://info.comodo.priv.at -- Debian Developer https://www.debian.org
 : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D  85FA BB3A 6801 8649 AA06
 `. `'  Member VIBE!AT & SPI Inc. -- Supporter Free Software Foundation Europe
   `-   

[toc] | [prev] | [next] | [standalone]


#1188925 — Bug#1064058: Bug#1050336: Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled

Fromgregor herrmann <gregoa@debian.org>
Date2024-03-03 16:30 +0100
SubjectBug#1064058: Bug#1050336: Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled
Message-ID<IdVWN-eaeX-7@gated-at.bofh.it>
In reply to#1186564

[Multipart message — attachments visible in raw view] — view raw

On Sun, 18 Feb 2024 01:41:20 +0100, gregor herrmann via pkg-perl-maintainers wrote:

> If yes, I'm happy to
> - do some BTS manipulation
> - more relevant: get this fix into bookworm for the next point
>   release.

Fixed package uploaded to bookworm right now, and unblock request
filed: #1065376

Cheers,
gregor

-- 
 .''`.  https://info.comodo.priv.at -- Debian Developer https://www.debian.org
 : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D  85FA BB3A 6801 8649 AA06
 `. `'  Member VIBE!AT & SPI Inc. -- Supporter Free Software Foundation Europe
   `-   

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web