From: Aaron Patterson Date: 2010-09-09T03:42:08+09:00 Subject: [ruby-core:32168] Re: [Ruby-Bug#3150] net/https peer verification doesn't do anything --9jxsPFA5p3P2qPhR Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Mon, Sep 06, 2010 at 11:26:01AM +0900, Hiroshi NAKAMURA wrote: > Issue #3150 has been updated by Hiroshi NAKAMURA. >=20 >=20 > Thanks Aaron. Hope we can identify the cause soon. Hi! I *think* I have good news. I am starting to suspect this is not a bug of Ruby. First (for posterity), here is a chunk of Ruby code to reproduce the problem without using net/http: require 'socket' require 'openssl' =20 s =3D TCPSocket.new 'bugzilla.redhat.com', 443 ctx =3D OpenSSL::SSL::SSLContext.new ctx.verify_mode =3D OpenSSL::SSL::VERIFY_PEER s =3D OpenSSL::SSL::SSLSocket.new s, ctx s.connect This code raises an exception on my linux machine, but not on my Snow Leopard machine. I wrote a (mostly) equivalent program in C here: http://gist.github.com/570593 On my Snow Leopard machine, SSL_connect() returns a value greater than 0. On my linux machine, this program results in an error. This program leads me to believe this is not a bug of Ruby, but I don't know why the behavior is different on linux vs OS X. I am still researching. --=20 Aaron Patterson http://tenderlovemaking.com/ --9jxsPFA5p3P2qPhR Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (Darwin) iQEcBAEBAgAGBQJMh9jxAAoJEJUxcLy0/6/GGYkIAIMRpyuaUUG9KfmxhwjMf35f eOOoP/KVaKfF1u4ow9f60lfByhAJMAz5MBb42zUk39dnpGrBFNhN2lTAS+iYvZA4 BRKvmwJ/hapm+Lu/TZGLeDvJCJG+mKgOs8F/U/8etN6A+VFVFWxSO/60Oha0RKhI C3bVSdNQ6qnjNq/rlcesGevenVCAgiM75RiJ0MHQZclOy8HmTDK5POEsVtYdEgWN +axSdoJ/QGpt9YJRp/yehFZq4wMlDP1z801KpFeypoIiPLlcYPcF+NYB/Et4SB78 pz56USUsND0l93Wb8A03spgX5VqoIfdoxJVG1nzMnGEMmiG1hbIb41mI6+tPHcc= =a/Zq -----END PGP SIGNATURE----- --9jxsPFA5p3P2qPhR--