From: Joseph Jones Date: 2015-12-17T21:06:46-07:00 Subject: [ruby-core:72283] [Ruby trunk - Bug #11401] Net::HTTP SSL session resumption does not send SNI --56738656_6de91b18_16c Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Joseph Jones liked your message with Boxer. On November 30, 2015 at 05:17= :42 MST, usa=40garbagecollect.jp wrote:Issue =2311401 has been updated by= Usaku NAKAMURA.Backport changed from 2.0.0: REQUIRED, 2.1: REQUIRED, 2.2= : DONE to 2.0.0: REQUIRED, 2.1: DONE, 2.2: DONEruby=5F2=5F1 r52799 merged= revision(s) 52682.----------------------------------------Bug =2311401: = Net::HTTP SSL session resumption does not send SNIhttps://bugs.ruby-lang.= org/issues/11401=23change-55162* Author: Michiel Karnebeek* Status: Close= d* Priority: Normal* Assignee: openssl* ruby -v: * Backport: 2.0.0: REQUI= RED, 2.1: DONE, 2.2: DONE----------------------------------------See http= s://github.com/ruby/ruby/pull/964=23=23 ProblemWhen an initial SSL reques= t is done, Net::HTTP stores the OpenSSL::SSL::Session object in =40ssl=5F= session.When (after the http-keep-alive timeout has expired, or the conne= ction was closed for some other reason) a second http request is made by = Net::Http, resulting in calling Net::Http=23connect (see the relevant pie= ces of code below, while reading the following points).* =23connect first= calls =60OpenSSL::SSL::SSLSocket=23session=3D=60 at http.rb:924, which, = in C code, eventually calls the C-method ossl=5Fssl=5Fsetup * which execu= tes the =60if(=21ssl) =7B=60 block at ossl=5Fssl.c:1205, but since =40hos= tname has not been set yet, it will not execute SSL=5Fset=5Ftlsext=5Fhost= =5Fname. Also, because the OpenSSL::SSL::Session object does not contain = a hostname, it is not known to OpenSSL at this point.* it then calls =60O= penSSL::SSL::SSLSocket=23hostname=3D=60 at http.rb:927 which only sets =40= hostname on OpenSSL::SSL::SSLSocket* and then it calls =60OpenSSL::SSL::S= SLSocket=23connect=60 at http.rb:941 * which is doing the second call to = the C-method ossl=5Fssl=5Fsetup, but since the =60if(=21ssl) =7B=60 alrea= dy ran, it won't run again, and won't set the hostname from =40hostname t= o SSL=5Fset=5Ftlsext=5Fhost=5Fname.This causes the second request to cont= ains a SSL Session Ticket, but not a SNI header. This is easily verified = by doing 2 calls in a ruby script, with a sleep 2.1 in between (http-keep= -alive timeout is 2 seconds by default) and checking the second Client He= llo message in Wireshark.Normally this does not cause any issues, because= the server looks at the SSL Session Ticket and knows for which virtual h= ost it issued the ticket. So when a second request comes in with that tic= ket, it assumes the request should be handled by that vhost.However, this= breaks when the client (Ruby) thinks the session ticket is still valid (= =2310533 did some fixing), sends it to the server, but the server denies = it. The server then starts to renegotiate the SSL session, but since the = SNI header is missing, it won't know for which vhost, and sends the SSL c= ertificate for the default vhost, which may not be the vhost it wants to = connect to. The client (Ruby) then checks the certificate against the hos= tname it was connecting to, and finds out it doesn't match.So, this only = occurs on SSL session resumption (the second http request after http-keep= -alive expired, or the connection was closed), when connecting to non-def= ault vhosts which has a different certificate set than the default vhost,= and when the client thinks the SSL Session Ticket is valid, but the serv= er disagrees.Why would the server deny the SSL session ticket=3F The clie= nt already checked if it was valid, right=3F Well, all kind of reasons:* = Server may have invalidated the ticket earlier than the client* Server re= booted* Time drift* ...* but mostly because the SSL termination for a spe= cific hostname may be handled by multiple servers, which are not sharing = their SSL session tickets (or sharing them in a delayed matter).=23=23 So= lutionThe solution is to move the call to =60OpenSSL::SSL::SSLSocket=23ho= stname=3D=60 before the call to =60OpenSSL::SSL::SSLSocket=23session=3D=60= , so the hostname gets set when ossl=5Fssl=5Fset=5Fsession calls ossl=5Fs= sl=5Fsetup=23=23 Relevant code pieceshttp.rb=7E=7E=7E868 def connect...87= 8 s =3D Timeout.timeout(=40open=5Ftimeout, Net::OpenTimeout) =7B...885 =7D= 886 s.setsockopt(Socket::IPPROTO=5FTCP, Socket::TCP=5FNODELAY, 1)887 D =22= opened=22888 if use=5Fssl=3F...897 =40ssl=5Fcontext =3D OpenSSL::SSL::SSL= Context.new898 =40ssl=5Fcontext.set=5Fparams(ssl=5Fparameters)899 D =22st= arting SSL for =23=7Bconn=5Faddress=7D:=23=7Bconn=5Fport=7D...=22900 s =3D= OpenSSL::SSL::SSLSocket.new(s, =40ssl=5Fcontext) 901 s.sync=5Fclose =3D = true902 D =22SSL established=22903 end904 =40socket =3D BufferedIO.new(s)= ...908 if use=5Fssl=3F909 begin910 if proxy=3F...921 end922 if =40ssl=5Fs= ession and923 Process.clock=5Fgettime(Process::CLOCK=5FREALTIME) 924 s.se= ssion =3D =40ssl=5Fsession if =40ssl=5Fsession (calls the C-method ossl=5F= ssl=5Fsetup) also, this does not set the hostname, as OpenSSL::SSL::Sess= ion does not contain a hostname925 end926 =23 Server Name Indication (SNI= ) R=46C 3546927 s.hostname =3D =40address if s.respond=5Fto=3F :hostname=3D= It relies on ossl=5Fssl=5Fsetup to actually set it to openssl (SSL=5Fs= et=5Ftlsext=5Fhost=5Fname at ossl=5Fssl.c:1221928 if timeout =3D =40open=5F= timeout929 while true930 raise Net::OpenTimeout if timeout 931 start =3D = Process.clock=5Fgettime Process::CLOCK=5FMONOTONIC932 =23 to=5Fio is requ= ied because SSLSocket doesn't have wait=5Freadable yet933 case s.connect=5F= nonblock(exception: false)934 when :wait=5Freadable; s.to=5Fio.wait=5Frea= dable(timeout)935 when :wait=5Fwritable; s.to=5Fio.wait=5Fwritable(timeou= t)936 else; break937 end938 timeout -=3D Process.clock=5Fgettime(Process:= :CLOCK=5FMONOTONIC) - start939 end940 else941 s.connect but does not set= up hostname, as it already ran once (see ossl=5Fssl.c:1205)942 end943 if= =40ssl=5Fcontext.verify=5Fmode =21=3D OpenSSL::SSL::VERI=46Y=5FNONE944 s= .post=5Fconnection=5Fcheck(=40address)945 end946 =40ssl=5Fsession =3D s.s= ession 947 rescue =3D> exception948 D =22Conn close because of connect er= ror =23=7Bexception=7D=22949 =40socket.close if =40socket and not =40sock= et.closed=3F950 raise exception951 end952 end953 on=5Fconnect954 end=7E=7E= =7Eossl=5Fssl.c=7E=7E=7E101 static const char *ossl=5Fssl=5Fattrs=5B=5D =3D= =7B102 =23ifdef HAVE=5FSSL=5FSET=5FTLSEXT=5FHOST=5FNAME103 =22hostname=22= ,104 =23endif105 =22sync=5Fclose=22,106 =7D;...1330 ossl=5Fssl=5Fconnect(= VALUE self)1331 =7B1332 ossl=5Fssl=5Fsetup(self);1333 return ossl=5Fstart= =5Fssl(self, SSL=5Fconnect, =22SSL=5Fconnect=22, 0, 0);1334 =7D...1197 os= sl=5Fssl=5Fsetup(VALUE self) 1198 =7B 1199 VALUE io, v=5Fctx, cb; 1200 SS= L=5FCTX *ctx; 1201 SSL *ssl; 1202 rb=5Fio=5Ft *fptr; 1203 1204 GetSSL(sel= f, ssl); 1205 if(=21ssl)=7B 1206 =23ifdef HAVE=5FSSL=5FSET=5FTLSEXT=5FHOS= T=5FNAME 1207 VALUE hostname =3D rb=5Fiv=5Fget(self, =22=40hostname=22);1= 208 =23endif 1209 1210 v=5Fctx =3D ossl=5Fssl=5Fget=5Fctx(self); 1211 Get= SSLCTX(v=5Fctx, ctx); 1212 1213 ssl =3D SSL=5Fnew(ctx); 1214 if (=21ssl) = =7B 1215 ossl=5Fraise(eSSLError, =22SSL=5Fnew=22); 1216 =7D 1217 DATA=5FP= TR(self) =3D ssl; 1218 1219 =23ifdef HAVE=5FSSL=5FSET=5FTLSEXT=5FHOST=5FN= AME 1220 if (=21NIL=5FP(hostname)) =7B 1221 if (SSL=5Fset=5Ftlsext=5Fhost= =5Fname(ssl, StringValuePtr(hostname)) =21=3D 1) 1222 ossl=5Fraise(eSSLEr= ror, =22SSL=5Fset=5Ftlsext=5Fhost=5Fname=22); 1223 =7D 1224 =23endif 1225= io =3D ossl=5Fssl=5Fget=5Fio(self); 1226 GetOpen=46ile(io, fptr); 1227 r= b=5Fio=5Fcheck=5Freadable(fptr); 1228 rb=5Fio=5Fcheck=5Fwritable(fptr); 1= 229 SSL=5Fset=5Ffd(ssl, TO=5FSOCKET(=46PTR=5FTO=5F=46D(fptr))); 1230 SSL=5F= set=5Fex=5Fdata(ssl, ossl=5Fssl=5Fex=5Fptr=5Fidx, (void*)self);1231 cb =3D= ossl=5Fsslctx=5Fget=5Fverify=5Fcb(v=5Fctx);1232 SSL=5Fset=5Fex=5Fdata(ss= l, ossl=5Fssl=5Fex=5Fvcb=5Fidx, (void*)cb);1233 cb =3D ossl=5Fsslctx=5Fge= t=5Fclient=5Fcert=5Fcb(v=5Fctx);1234 SSL=5Fset=5Fex=5Fdata(ssl, ossl=5Fss= l=5Fex=5Fclient=5Fcert=5Fcb=5Fidx, (void*)cb);1235 cb =3D ossl=5Fsslctx=5F= get=5Ftmp=5Fdh=5Fcb(v=5Fctx);1236 SSL=5Fset=5Fex=5Fdata(ssl, ossl=5Fssl=5F= ex=5Ftmp=5Fdh=5Fcallback=5Fidx, (void*)cb);1237 SSL=5Fset=5Finfo=5Fcallba= ck(ssl, ssl=5Finfo=5Fcb);1238 =7D 1239 1240 return Qtrue; 1241 =7D ...182= 5 ossl=5Fssl=5Fset=5Fsession(VALUE self, VALUE arg1)1826 =7B1827 SSL *ssl= ;1828 SSL=5FSESSION *sess;1829 1830 /* why is ossl=5Fssl=5Fsetup delayed=3F= */1831 ossl=5Fssl=5Fsetup(self);1832 1833 ossl=5Fssl=5Fdata=5Fget=5Fstru= ct(self, ssl);1834 1835 SafeGetSSLSession(arg1, sess);1836 1837 if (SSL=5F= set=5Fsession(ssl, sess) =21=3D 1)1838 ossl=5Fraise(eSSLError, =22SSL=5Fs= et=5Fsession=22);1839 1840 return arg1;1841 =7D=7E=7E=7EPatch to http.rb:= =7E=7E=7E=40=40 -914,12 +914,12 =40=40 module Net =23:nodoc: =40socket.wr= ite(buf) HTTPResponse.read=5Fnew(=40socket).value end+ =23 Server Name In= dication (SNI) R=46C 3546+ s.hostname =3D =40address if s.respond=5Fto=3F= :hostname=3D if =40ssl=5Fsession and Process.clock=5Fgettime(Process::CL= OCK=5FREALTIME) s.session =3D =40ssl=5Fsession if =40ssl=5Fsession end- = =23 Server Name Indication (SNI) R=46C 3546- s.hostname =3D =40address if= s.respond=5Fto=3F :hostname=3D Timeout.timeout(=40open=5Ftimeout, Net::O= penTimeout) =7B s.connect =7D if =40ssl=5Fcontext.verify=5Fmode =21=3D Op= enSSL::SSL::VERI=46Y=5FNONE s.post=5Fconnection=5Fcheck(=40address)=7E=7E= =7E---=46iles--------------------------------net.http.bug.patch (884 Byte= s)-- https://bugs.ruby-lang.org/ --56738656_6de91b18_16c Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Joseph Jones liked your message with Boxer.


= On November 30, 2015 at 05:17:42 MST, usa=40garbagecollect.jp wrote:
=
Issue =2311401 has been up= dated by Usaku NAKAMURA.

Backport changed from 2.0.0: REQUIRED= , 2.1: REQUIRED, 2.2: DONE to 2.0.0: REQUIRED, 2.1: DONE, 2.2: DONE
=
ruby=5F2=5F1 r52799 merged revision(s) 52682.

----------= ------------------------------
Bug =2311401: Net::HTTP SSL session r= esumption does not send SNI
https://bugs.ruby-lang.org/issues/11401=23= change-55162

* Author: Michiel Karnebeek
* Status: Closed=
* Priority: Normal
* Assignee: openssl
* ruby -v:
*= Backport: 2.0.0: REQUIRED, 2.1: DONE, 2.2: DONE
-------------------= ---------------------
See https://github.com/ruby/ruby/pull/964

=23=23 Problem

When an initial SSL request is done, Net= ::HTTP stores the OpenSSL::SSL::Session object in =40ssl=5Fsession.
=
When (after the http-keep-alive timeout has expired, or the connect= ion was closed for some other reason) a second http request is made by Ne= t::Http, resulting in calling Net::Http=23connect (see the relevant piece= s of code below, while reading the following points).

* =23con= nect first calls =60OpenSSL::SSL::SSLSocket=23session=3D=60 at http.rb:92= 4, which, in C code, eventually calls the C-method ossl=5Fssl=5Fsetup
* which executes the =60if(=21ssl) =7B=60 block at ossl=5Fssl.c:1205, = but since =40hostname has not been set yet, it will not execute SSL=5Fset= =5Ftlsext=5Fhost=5Fname. Also, because the OpenSSL::SSL::Session object d= oes not contain a hostname, it is not known to OpenSSL at this point.
* it then calls =60OpenSSL::SSL::SSLSocket=23hostname=3D=60 at http.rb:= 927 which only sets =40hostname on OpenSSL::SSL::SSLSocket
* and the= n it calls =60OpenSSL::SSL::SSLSocket=23connect=60 at http.rb:941
*= which is doing the second call to the C-method ossl=5Fssl=5Fsetup, but s= ince the =60if(=21ssl) =7B=60 already ran, it won't run again, and won't = set the hostname from =40hostname to SSL=5Fset=5Ftlsext=5Fhost=5Fname.
This causes the second request to contains a SSL Session Ticket,= but not a SNI header. This is easily verified by doing 2 calls in a ruby= script, with a sleep 2.1 in between (http-keep-alive timeout is 2 second= s by default) and checking the second Client Hello message in Wireshark.<= br />
Normally this does not cause any issues, because the server lo= oks at the SSL Session Ticket and knows for which virtual host it issued = the ticket. So when a second request comes in with that ticket, it assume= s the request should be handled by that vhost.

However, this b= reaks when the client (Ruby) thinks the session ticket is still valid (=23= 10533 did some fixing), sends it to the server, but the server denies it.= The server then starts to renegotiate the SSL session, but since the SNI= header is missing, it won't know for which vhost, and sends the SSL cert= ificate for the default vhost, which may not be the vhost it wants to con= nect to. The client (Ruby) then checks the certificate against the hostna= me it was connecting to, and finds out it doesn't match.

So, t= his only occurs on SSL session resumption (the second http request after = http-keep-alive expired, or the connection was closed), when connecting t= o non-default vhosts which has a different certificate set than the defau= lt vhost, and when the client thinks the SSL Session Ticket is valid, but= the server disagrees.

Why would the server deny the SSL sessi= on ticket=3F The client already checked if it was valid, right=3F Well, a= ll kind of reasons:

* Server may have invalidated the ticket e= arlier than the client
* Server rebooted
* Time drift
* ..= .
* but mostly because the SSL termination for a specific hostname m= ay be handled by multiple servers, which are not sharing their SSL sessio= n tickets (or sharing them in a delayed matter).

=23=23 Soluti= on
The solution is to move the call to =60OpenSSL::SSL::SSLSocket=23= hostname=3D=60 before the call to =60OpenSSL::SSL::SSLSocket=23session=3D= =60, so the hostname gets set when ossl=5Fssl=5Fset=5Fsession calls ossl=5F= ssl=5Fsetup

=23=23 Relevant code pieces

http.rb

=7E=7E=7E
868 def connect
...
878 s =3D = Timeout.timeout(=40open=5Ftimeout, Net::OpenTimeout) =7B
...
88= 5 =7D
886 s.setsockopt(Socket::IPPROTO=5FTCP, Socket::TC= P=5FNODELAY, 1)
887 D =22opened=22
888 if use=5Fssl= =3F
...
897 =40ssl=5Fcontext =3D OpenSSL::SSL::SSLConte= xt.new
898 =40ssl=5Fcontext.set=5Fparams(ssl=5Fparameters)899 D =22starting SSL for =23=7Bconn=5Faddress=7D:=23=7Bconn=5F= port=7D...=22
900 s =3D OpenSSL::SSL::SSLSocket.new(s, =40ss= l=5Fcontext) <-- it always re-creates the OpenSSL::SSL::SSLS= ocket object
901 s.sync=5Fclose =3D true
902 D = =22SSL established=22
903 end
904 =40socket =3D Buf= feredIO.new(s)
...
908 if use=5Fssl=3F
909 b= egin
910 if proxy=3F
...
921 end
= 922 if =40ssl=5Fsession and
923 Process.clock= =5Fgettime(Process::CLOCK=5FREALTIME) < =40ssl=5Fsession.time.to=5Ff + =40= ssl=5Fsession.timeout
924 s.session =3D =40ssl=5Fsession= if =40ssl=5Fsession <-- (2nd request) this call already = sets up the connection
= (calls the C-method ossl=5Fssl=5Fset= up)
= also, this does not set the hostname,
= as O= penSSL::SSL::Session does not contain a hostname
925 end926 =23 Server Name Indication (SNI) R=46C 3546
927 = s.hostname =3D =40address if s.respond=5Fto=3F :hostname=3D = <-- Only sets the hostname to =40hostname on OpenSSL::SSL::SSLSocket.=
= It relies on ossl=5Fssl=5Fsetup to actually set it to opens= sl
= (SSL=5Fset=5Ftlsext=5Fhost=5Fname at ossl=5Fssl.c:1221928 if timeout =3D =40open=5Ftimeout
929 w= hile true
930 raise Net::OpenTimeout if timeout <=3D 0=
931 start =3D Process.clock=5Fgettime Process::CLOCK=5F= MONOTONIC
932 =23 to=5Fio is requied because SSLSocket= doesn't have wait=5Freadable yet
933 case s.connect=5F= nonblock(exception: false)
934 when :wait=5Freadable; = s.to=5Fio.wait=5Freadable(timeout)
935 when :wait=5Fwr= itable; s.to=5Fio.wait=5Fwritable(timeout)
936 else; b= reak
937 end
938 timeout -=3D Proce= ss.clock=5Fgettime(Process::CLOCK=5FMONOTONIC) - start
939 = end
940 else
941 s.connect = <-- triggers another call to the C-me= thod ossl=5Fssl=5Fsetup,
= but does not set up hostname, as i= t already ran once
= (see ossl=5Fssl.c:1205)
942 = end
943 if =40ssl=5Fcontext.verify=5Fmode =21=3D OpenSSL:= :SSL::VERI=46Y=5FNONE
944 s.post=5Fconnection=5Fcheck(=40= address)
945 end
946 =40ssl=5Fsession =3D s= .session <-- (1st request) does not sto= re hostname, so the call at line 924 does not set it.
947 re= scue =3D> exception
948 D =22Conn close because of connect= error =23=7Bexception=7D=22
949 =40socket.close if =40soc= ket and not =40socket.closed=3F
950 raise exception
9= 51 end
952 end
953 on=5Fconnect
954 = end
=7E=7E=7E

ossl=5Fssl.c

=7E=7E=7E
10= 1 static const char *ossl=5Fssl=5Fattrs=5B=5D =3D =7B
102 =23i= fdef HAVE=5FSSL=5FSET=5FTLSEXT=5FHOST=5FNAME
103 =22hostname=22= ,
104 =23endif
105 =22sync=5Fclose=22,
106 =7D= ;
...
1330 ossl=5Fssl=5Fconnect(VALUE self)
1331 =7B=
1332 ossl=5Fssl=5Fsetup(self);
1333 return ossl=5F= start=5Fssl(self, SSL=5Fconnect, =22SSL=5Fconnect=22, 0, 0);
1334 = =7D
...
1197 ossl=5Fssl=5Fsetup(VALUE self)
1198 = =7B
1199 VALUE io, v=5Fctx, cb;
1200 SS= L=5FCTX *ctx;
1201 SSL *ssl;
1202 rb=5Fio= =5Ft *fptr;
1203
1204 GetSSL(self, ssl); =
1205 if(=21ssl)=7B
1206 =23ifdef HAVE=5FSSL=5FSE= T=5FTLSEXT=5FHOST=5FNAME
1207 VALUE hostname =3D rb=5Fiv=5F= get(self, =22=40hostname=22);
1208 =23endif
1209 =
1210 v=5Fctx =3D ossl=5Fssl=5Fget=5Fctx(self);
= 1211 GetSSLCTX(v=5Fctx, ctx);
1212
1213 = ssl =3D SSL=5Fnew(ctx);
1214 if (=21ssl) =7B=
1215 ossl=5Fraise(eSSLError, =22SSL=5Fnew=22); =
1216 =7D
1217 DATA=5FPTR(self) =3D= ssl;
1218
1219 =23ifdef HAVE=5FSSL=5FSET=5FTLSE= XT=5FHOST=5FNAME
1220 if (=21NIL=5FP(hostname)) =7B =
1221 if (SSL=5Fset=5Ftlsext=5Fhost=5Fname(ssl, Stri= ngValuePtr(hostname)) =21=3D 1)
1222 ossl=5Fra= ise(eSSLError, =22SSL=5Fset=5Ftlsext=5Fhost=5Fname=22);
1223 = =7D
1224 =23endif
1225 io =3D oss= l=5Fssl=5Fget=5Fio(self);
1226 GetOpen=46ile(io, fptr= );
1227 rb=5Fio=5Fcheck=5Freadable(fptr);
12= 28 rb=5Fio=5Fcheck=5Fwritable(fptr);
1229 = SSL=5Fset=5Ffd(ssl, TO=5FSOCKET(=46PTR=5FTO=5F=46D(fptr)));
1230= SSL=5Fset=5Fex=5Fdata(ssl, ossl=5Fssl=5Fex=5Fptr=5Fidx, (void= *)self);
1231 cb =3D ossl=5Fsslctx=5Fget=5Fverify=5Fcb(v=5F= ctx);
1232 SSL=5Fset=5Fex=5Fdata(ssl, ossl=5Fssl=5Fex=5Fv= cb=5Fidx, (void*)cb);
1233 cb =3D ossl=5Fsslctx=5Fget=5Fc= lient=5Fcert=5Fcb(v=5Fctx);
1234 SSL=5Fset=5Fex=5Fdata(ss= l, ossl=5Fssl=5Fex=5Fclient=5Fcert=5Fcb=5Fidx, (void*)cb);
1235 = cb =3D ossl=5Fsslctx=5Fget=5Ftmp=5Fdh=5Fcb(v=5Fctx);
1236 = SSL=5Fset=5Fex=5Fdata(ssl, ossl=5Fssl=5Fex=5Ftmp=5Fdh=5Fcallback=5F= idx, (void*)cb);
1237 SSL=5Fset=5Finfo=5Fcallback(ssl, ss= l=5Finfo=5Fcb);
1238 =7D
1239
1240 = return Qtrue;
1241 =7D
...
1825 ossl=5Fss= l=5Fset=5Fsession(VALUE self, VALUE arg1)
1826 =7B
1827 = SSL *ssl;
1828 SSL=5FSESSION *sess;
1829
183= 0 /* why is ossl=5Fssl=5Fsetup delayed=3F */
1831 ossl=5Fs= sl=5Fsetup(self);
1832
1833 ossl=5Fssl=5Fdata=5Fget=5F= struct(self, ssl);
1834
1835 SafeGetSSLSession(arg1,= sess);
1836
1837 if (SSL=5Fset=5Fsession(ssl, sess)= =21=3D 1)
1838 ossl=5Fraise(eSSLError, =22SSL=5Fset=5Fse= ssion=22);
1839
1840 return arg1;
1841 =7D
=7E=7E=7E

Patch to http.rb:

=7E=7E=7E

=40=40 -914,12 +914,12 =40=40 module Net =23:nodoc:
= =40socket.write(buf)
HTTPResponse.read=5Fnew(=40= socket).value
end
+ =23 Server Name Indicat= ion (SNI) R=46C 3546
+ s.hostname =3D =40address if s.respo= nd=5Fto=3F :hostname=3D
if =40ssl=5Fsession and
= Process.clock=5Fgettime(Process::CLOCK=5FREALTIME) < =40ssl=5Fs= ession.time.to=5Ff + =40ssl=5Fsession.timeout
s.session= =3D =40ssl=5Fsession if =40ssl=5Fsession
end
- = =23 Server Name Indication (SNI) R=46C 3546
- s.hostna= me =3D =40address if s.respond=5Fto=3F :hostname=3D
Timeo= ut.timeout(=40open=5Ftimeout, Net::OpenTimeout) =7B s.connect =7D
= if =40ssl=5Fcontext.verify=5Fmode =21=3D OpenSSL::SSL::VERI=46Y=5F= NONE
s.post=5Fconnection=5Fcheck(=40address)
=7E=7E= =7E

---=46iles--------------------------------
net.http.b= ug.patch (884 Bytes)


--
https://bugs.ruby-lang.org= /
--56738656_6de91b18_16c--