Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1186406 > unrolled thread
| Started by | Manfred Stock <m-debian@nfred.ch> |
|---|---|
| First post | 2024-02-16 16:10 +0100 |
| Last post | 2024-03-03 16:30 +0100 |
| Articles | 5 — 2 participants |
Back to article view | Back to linux.debian.bugs.dist
Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled Manfred Stock <m-debian@nfred.ch> - 2024-02-16 16:10 +0100
Bug#1050336: Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled gregor herrmann <gregoa@debian.org> - 2024-02-18 01:50 +0100
Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled Manfred Stock <m-debian@nfred.ch> - 2024-02-19 21:10 +0100
Bug#1032868: Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled gregor herrmann <gregoa@debian.org> - 2024-02-21 21:00 +0100
Bug#1064058: Bug#1050336: Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled gregor herrmann <gregoa@debian.org> - 2024-03-03 16:30 +0100
| From | Manfred Stock <m-debian@nfred.ch> |
|---|---|
| Date | 2024-02-16 16:10 +0100 |
| Subject | Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled |
| Message-ID | <I880F-ayDC-17@gated-at.bofh.it> |
Package: libxml-stream-perl Version: 1.24-4 Severity: normal Tags: upstream Control: affects -1 sendxmpp libnet-xmpp-perl Dear Maintainers, after upgrading to Debian Bookworm, we noticed that the sendxmpp command line tool was not working anymore in our setup. During the investigation of this issue, I noticed that downgrading IO-Socket-SSL to the version in Bullseye made sendxmpp work again. I then started to try all versions of IO-Socket-SSL between the version in Bullseye and the one in Bookworm and found that it stopped working with version 2.078. Eventually, I came up with a pull request [1] containing a patch that fixed it for us - apparently, the way XML-Stream was using IO-Socket-SSL most likely always resulted in the hostname verification to be done against the IP address of the peer instead of an actual hostname, which was always considered to be successful in IO-Socket-SSL < 2.078, but not anymore in newer versions. Since the upstream seems quite inactive, it might be worth considering to add this or a similar patch to the package in Debian, as I came across several other bug reports in the Debian BTS which might actually be caused by this issue, like #986971 [2], #1032868 [3] and maybe also #1050336 [4] - at least the error messages in the first two look very similar to what I saw. Cheers, Manfred [1]: https://github.com/dap/XML-Stream/pull/28 [2]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=986971 [3]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1032868 [4]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1050336 -- System Information: Debian Release: 12.5 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable') Architecture: amd64 (x86_64) Kernel: Linux 6.1.0-18-amd64 (SMP w/4 CPU threads; PREEMPT) Kernel taint flags: TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE Locale: LANG=de_CH.utf8, LC_CTYPE=de_CH.utf8 (charmap=UTF-8), LANGUAGE=de_CH:de Shell: /bin/sh linked to /usr/bin/dash Init: unable to detect Versions of packages libxml-stream-perl depends on: ii libauthen-sasl-perl 2.1600-3 ii libio-socket-ssl-perl 2.081-2 ii perl 5.36.0-7+deb12u1 libxml-stream-perl recommends no packages. Versions of packages libxml-stream-perl suggests: ii libnet-dns-perl 1.36-1 -- no debconf information
[toc] | [next] | [standalone]
| From | gregor herrmann <gregoa@debian.org> |
|---|---|
| Date | 2024-02-18 01:50 +0100 |
| Subject | Bug#1050336: Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled |
| Message-ID | <I8Dxy-aRz3-59@gated-at.bofh.it> |
| In reply to | #1186406 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, 16 Feb 2024 15:56:04 +0100, Manfred Stock wrote: > after upgrading to Debian Bookworm, we noticed that the sendxmpp command > line tool was not working anymore in our setup. During the investigation > of this issue, I noticed that downgrading IO-Socket-SSL to the version > in Bullseye made sendxmpp work again. I then started to try all versions > of IO-Socket-SSL between the version in Bullseye and the one in Bookworm > and found that it stopped working with version 2.078. Eventually, I came > up with a pull request [1] containing a patch that fixed it for us - > apparently, the way XML-Stream was using IO-Socket-SSL most likely > always resulted in the hostname verification to be done against the IP > address of the peer instead of an actual hostname, which was always > considered to be successful in IO-Socket-SSL < 2.078, but not anymore in > newer versions. Oh wow -- thank you! I remember looking at #1050336 in libnet-xmpp-perl and having the suspicion that the problem is actually in libxml-stream-perl, but never managed to nail it down. > Since the upstream seems quite inactive, it might be worth considering > to add this or a similar patch to the package in Debian, as I came > across several other bug reports in the Debian BTS which might actually > be caused by this issue, like #986971 [2], #1032868 [3] and maybe also > #1050336 [4] - at least the error messages in the first two look very > similar to what I saw. I've uploaded libxml-stream-perl 1.24-5 to unstable right now. I'd like to invite the submitters of the other bugs to tests if there problems are fixed with libxml-stream-perl 1.24-5. If yes, I'm happy to - do some BTS manipulation - more relevant: get this fix into bookworm for the next point release. Thanks again, gregor -- .''`. https://info.comodo.priv.at -- Debian Developer https://www.debian.org : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D 85FA BB3A 6801 8649 AA06 `. `' Member VIBE!AT & SPI Inc. -- Supporter Free Software Foundation Europe `-
[toc] | [prev] | [next] | [standalone]
| From | Manfred Stock <m-debian@nfred.ch> |
|---|---|
| Date | 2024-02-19 21:10 +0100 |
| Message-ID | <I9i7D-bgzN-1@gated-at.bofh.it> |
| In reply to | #1186564 |
Hi gregor, Am Sun, Feb 18, 2024 at 01:41:20AM +0100 schrieb gregor herrmann: > On Fri, 16 Feb 2024 15:56:04 +0100, Manfred Stock wrote: > > > after upgrading to Debian Bookworm, we noticed that the sendxmpp command > > line tool was not working anymore in our setup. [...] Eventually, I came > > up with a pull request [1] containing a patch that fixed it for us - > > [...] > > Oh wow -- thank you! you're welcome, and thanks for your quick response! > I remember looking at #1050336 in libnet-xmpp-perl and having the > suspicion that the problem is actually in libxml-stream-perl, but > never managed to nail it down. It actually took me a while, too ;). I think I ended up in XML-Stream because of the debug output, especially the binary part that was printed in the output of a read operation. A few detours later, I found the IO-Socket-SSL release where it stopped working and remembered that start_SSL() was called in XML::Stream and that an example in the documentation somewhere passed a hostname, which wasn't done in XML::Stream. In conclusion, the error handling in XML::Stream (and maybe Net::XMPP as well) seems to have some room for improvement, and I also noticed that some messages in the debug output are quite misleading (the "We are secure", for example, that was printed in TLSClientProceed(), simply wasn't correct, at this point, upgrading the socket to SSL/TLS had failed). > > Since the upstream seems quite inactive, it might be worth considering > > to add this or a similar patch to the package in Debian, as I came > > across several other bug reports in the Debian BTS which might actually > > be caused by this issue, like #986971 [2], #1032868 [3] and maybe also > > #1050336 [4] - at least the error messages in the first two look very > > similar to what I saw. > > I've uploaded libxml-stream-perl 1.24-5 to unstable right now. Thanks! I quickly tested this package and can confirm that it works for me. > I'd like to invite the submitters of the other bugs to tests if there > problems are fixed with libxml-stream-perl 1.24-5. > > If yes, I'm happy to > - do some BTS manipulation > - more relevant: get this fix into bookworm for the next point > release. This would be great, thanks! Cheers, Manfred
[toc] | [prev] | [next] | [standalone]
| From | gregor herrmann <gregoa@debian.org> |
|---|---|
| Date | 2024-02-21 21:00 +0100 |
| Subject | Bug#1032868: Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled |
| Message-ID | <Ia0V3-bHrL-3@gated-at.bofh.it> |
| In reply to | #1186747 |
[Multipart message — attachments visible in raw view] — view raw
Control: reassign 1032868 libxml-stream-perl 1.24-4 Control: reassign 1050336 libxml-stream-perl 1.24-4 Control: fixed 1032868 1.24-5 Control: fixed 1050336 1.24-5 Control: tag 986971 bookworm sid trixie upstream Control: tag 1032868 bookworm sid trixie upstream Control: tag 1050336 bookworm sid trixie upstream On Mon, 19 Feb 2024 20:48:26 +0100, Manfred Stock wrote: > > I remember looking at #1050336 in libnet-xmpp-perl and having the > > suspicion that the problem is actually in libxml-stream-perl, but > > never managed to nail it down. > It actually took me a while, too ;). Heh :) > I think I ended up in XML-Stream > because of the debug output, especially the binary part that was printed > in the output of a read operation. A few detours later, I found the > IO-Socket-SSL release where it stopped working and remembered that > start_SSL() was called in XML::Stream and that an example in the > documentation somewhere passed a hostname, which wasn't done in > XML::Stream. And that was the nice finding. > > I've uploaded libxml-stream-perl 1.24-5 to unstable right now. > Thanks! I quickly tested this package and can confirm that it works for > me. Great, thanks. > > > I'd like to invite the submitters of the other bugs to tests if there > > problems are fixed with libxml-stream-perl 1.24-5. > > > > If yes, I'm happy to > > - do some BTS manipulation > > - more relevant: get this fix into bookworm for the next point > > release. > > This would be great, thanks! In #986971 Martin has already confirmed that libxml-stream-perl/1.24-5 fixes his issue, and the bug has been reassigned. I'm now reassigning the other 2 bugs and will merge them later. Cheers, gregor -- .''`. https://info.comodo.priv.at -- Debian Developer https://www.debian.org : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D 85FA BB3A 6801 8649 AA06 `. `' Member VIBE!AT & SPI Inc. -- Supporter Free Software Foundation Europe `-
[toc] | [prev] | [next] | [standalone]
| From | gregor herrmann <gregoa@debian.org> |
|---|---|
| Date | 2024-03-03 16:30 +0100 |
| Subject | Bug#1064058: Bug#1050336: Bug#1064058: libxml-stream-perl: TLS/SSL broken with IO-Socket-SSL >= 2.078 when hostname verification is enabled |
| Message-ID | <IdVWN-eaeX-7@gated-at.bofh.it> |
| In reply to | #1186564 |
[Multipart message — attachments visible in raw view] — view raw
On Sun, 18 Feb 2024 01:41:20 +0100, gregor herrmann via pkg-perl-maintainers wrote: > If yes, I'm happy to > - do some BTS manipulation > - more relevant: get this fix into bookworm for the next point > release. Fixed package uploaded to bookworm right now, and unblock request filed: #1065376 Cheers, gregor -- .''`. https://info.comodo.priv.at -- Debian Developer https://www.debian.org : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D 85FA BB3A 6801 8649 AA06 `. `' Member VIBE!AT & SPI Inc. -- Supporter Free Software Foundation Europe `-
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.bugs.dist
csiph-web