[#25636] [Oniguruma 3.X] reggnu.c — "K.Kosako" <sndgk393@...>
さっき気がついたのですが、元々は
15 messages
2005/02/05
[#25639] Re: [Oniguruma 3.X] reggnu.c
— Yukihiro Matsumoto <matz@...>
2005/02/05
まつもと ゆきひろです
[#25643] Re: [Oniguruma 3.X] reggnu.c
— "K.Kosako" <sndgk393@...>
2005/02/06
Yukihiro Matsumotoさんの
[#25702] Re: [Oniguruma 3.X] reggnu.c
— Kazuo Saito <ksaito@...>
2005/02/15
斉藤です。
[#25647] C level set_trace_func — Shugo Maeda <shugo@...>
前田です。
10 messages
2005/02/07
[#25696] Re: C level set_trace_func
— Yukihiro Matsumoto <matz@...>
2005/02/14
まつもと ゆきひろです
[#25697] Re: C level set_trace_func
— Shugo Maeda <shugo@...>
2005/02/14
前田です。
[#25655] openssl binding for SSL_CTX_set_default_verify_paths and X509_STORE_set_default_paths — Tanaka Akira <akr@...17n.org>
open-uri で https を扱うことを考えていろいろと調べていた所、openssl で、
9 messages
2005/02/08
[#25670] Re: openssl binding for SSL_CTX_set_default_verify_paths and X509_STORE_set_default_paths
— GOTOU Yuuzou <gotoyuzo@...>
2005/02/10
In message <876513vce0.fsf@serein.a02.aist.go.jp>,
[#25683] Re: openssl binding for SSL_CTX_set_default_verify_paths and X509_STORE_set_default_paths
— Tanaka Akira <akr@...17n.org>
2005/02/12
In article <20050211.053825.291449071.gotoyuzo@sawara.does.notwork.org>,
[#25684] Re: openssl binding for SSL_CTX_set_default_verify_paths and X509_STORE_set_default_paths
— Tanaka Akira <akr@...17n.org>
2005/02/12
In article <87psz6gcfh.fsf@serein.a02.aist.go.jp>,
[#25690] Re: openssl binding for SSL_CTX_set_default_verify_paths and X509_STORE_set_default_paths
— GOTOU Yuuzou <gotoyuzo@...>
2005/02/12
In message <87ll9thnng.fsf@serein.a02.aist.go.jp>,
[#25691] Re: openssl binding for SSL_CTX_set_default_verify_paths and X509_STORE_set_default_paths
— Tanaka Akira <akr@...17n.org>
2005/02/12
In article <20050213.021305.304099822.gotoyuzo@sawara.does.notwork.org>,
[#25700] BUG on thread and block? — sheepman <sheepman@...>
こんばんは、sheepman です。
2 messages
2005/02/15
[#25712] core dump with GC in rb_thread_save_context — Tanaka Akira <akr@...17n.org>
昨日の夜からとあるプログラム (五月雨) が 4回ばかり core を吐いていて、
5 messages
2005/02/17
[#25713] pthread trouble on sighandler — Hidetoshi NAGAI <nagai@...>
永井@知能.九工大です.
17 messages
2005/02/18
[#25714] Re: pthread trouble on sighandler
— Yukihiro Matsumoto <matz@...>
2005/02/18
まつもと ゆきひろです
[#25715] Re: pthread trouble on sighandler
— Hidetoshi NAGAI <nagai@...>
2005/02/18
永井@知能.九工大です.
[#25717] Re: pthread trouble on sighandler
— Yukihiro Matsumoto <matz@...>
2005/02/18
まつもと ゆきひろです
[#25719] Re: pthread trouble on sighandler
— Hidetoshi NAGAI <nagai@...>
2005/02/18
永井@知能.九工大です.
[#25726] named capture — Kazuhiro NISHIYAMA <zn@...>
西山和広です。
6 messages
2005/02/19
[#25741] Oniguruma 3.7.0 — Kazuo Saito <ksaito@...>
斉藤です。
7 messages
2005/02/21
[#25755] I/O operation differs signal handler — Minero Aoki <aamine@...>
青木です。
14 messages
2005/02/24
[#25756] Re: I/O operation differs signal handler
— Tanaka Akira <akr@...17n.org>
2005/02/24
In article <20050224091450P.aamine@loveruby.net>,
[#25758] Re: I/O operation differs signal handler
— Tanaka Akira <akr@...17n.org>
2005/02/24
In article <1109213650.235317.11155.nullmailer@x31.priv.netlab.jp>,
[#25759] Re: I/O operation differs signal handler
— Yukihiro Matsumoto <matz@...>
2005/02/24
まつもと ゆきひろです
[#25760] Re: I/O operation differs signal handler
— Tanaka Akira <akr@...17n.org>
2005/02/24
In article <1109224128.668484.13752.nullmailer@x31.priv.netlab.jp>,
[ruby-dev:25683] Re: openssl binding for SSL_CTX_set_default_verify_paths and X509_STORE_set_default_paths
From:
Tanaka Akira <akr@...17n.org>
Date:
2005-02-12 13:01:31 UTC
List:
ruby-dev #25683
In article <20050211.053825.291449071.gotoyuzo@sawara.does.notwork.org>,
GOTOU Yuuzou <gotoyuzo@notwork.org> writes:
> ところで、verify_modeのデフォルトはOpenSSLライブラリに任せて
> いるのですが、net/httpsではSSL_VERIFY_PEERをデフォルトにすべ
> きだったと考えるようになりました。せめてopen-uriではそうして
> はどうでしょうか。
後から [ruby-dev:25254] に気がついたのですが、次のように取り込んでも良
いでしょうか。
Index: lib/open-uri.rb
===================================================================
RCS file: /src/ruby/lib/open-uri.rb,v
retrieving revision 1.34
diff -u -p -r1.34 open-uri.rb
--- lib/open-uri.rb 12 Feb 2005 08:40:08 -0000 1.34
+++ lib/open-uri.rb 12 Feb 2005 12:58:36 -0000
@@ -243,6 +243,11 @@ module OpenURI
resp = nil
http.start {
+ if (http.verify_mode & OpenSSL::SSL::VERIFY_PEER) != 0
+ unless https_post_connection_check(http.peer_cert, target_host)
+ raise "SSL hostname not match"
+ end
+ end
req = Net::HTTP::Get.new(request_uri, header)
if options.include? :http_basic_authentication
user, pass = options[:http_basic_authentication]
@@ -279,6 +284,31 @@ module OpenURI
else
raise OpenURI::HTTPError.new(io.status.join(' '), io)
end
+ end
+
+ def OpenURI.https_post_connection_check(cert, hostname)
+ subject = cert.subject
+ subject.to_a.each{|oid, value|
+ if oid == "CN" && value == hostname
+ return true
+ end
+ }
+ cert.extensions.each{|ext|
+ if ext.oid == "subjectAltName"
+ general_names = ext.value.split(/,\s+/)
+ general_names.each{|name|
+ if /(:?DNS|IP Address):(.*)/ =~ name
+ reg = Regexp.escape($1)
+ reg = reg.gsub(%r!\\\*!, '[^.]+')
+ reg = Regexp.new('\A' + reg + '\z')
+ if reg.match(hostname)
+ return true
+ end
+ end
+ }
+ end
+ }
+ return false
end
class HTTPError < StandardError
--
[田中 哲][たなか あきら][Tanaka Akira]