From: mortee Date: 2007-11-06T13:34:43+09:00 Subject: Re: open-uri + OpenSSL dusty wrote: > On Nov 5, 8:51 pm, dusty wrote: >> On Oct 27, 12:26 pm, Matthew Lagace wrote: >> >> >> >>> Ok when I do that, it says: >>> ssl value changed, but session already started >>> dusty wrote: >>>> On Oct 27, 1:35 am, Matthew Lagace wrote: >>>>> Hello, >>>>> I am usring open-uri to open an https:// link and when it tries to read >>>>> it, I get the 'connect' : certificate verify failed error. How can I >>>>> bypass this SSL verification? >>>>> Thanks, >>>>> M >>>>> -- >>>>> Posted viahttp://www.ruby-forum.com/. >>>> Set the verify_mode to OpenSSL::SSL::VERIFY_NONE >>>> eg: >>>> http = Net::HTTP.new(host,port) >>>> http.use_ssl = true >>>> http.verify_mode = OpenSSL::SSL::VERIFY_NONE >>> -- >>> Posted viahttp://www.ruby-forum.com/. >> Sorry, I guess you can't do it with open-uri. Here is a patch: >> >> add this ssl_verify option to the top of the file. >> >> FROM: >> >> module OpenURI >> Options = { >> :proxy => true, >> :progress_proc => true, >> :content_length_proc => true, >> :http_basic_authentication => true, >> } >> >> TO: >> >> module OpenURI >> Options = { >> :proxy => true, >> :progress_proc => true, >> :content_length_proc => true, >> :http_basic_authentication => true, >> :ssl_verify => true >> } >> >> Change the part where it enables verification >> >> FROM: >> >> if target.class == URI::HTTPS >> require 'net/https' >> http.use_ssl = true >> http.enable_post_connection_check = true >> http.verify_mode = OpenSSL::SSL::VERIFY_PEER >> store = OpenSSL::X509::Store.new >> store.set_default_paths >> http.cert_store = store >> end >> >> TO: >> if target.class == URI::HTTPS >> require 'net/https' >> http.use_ssl = true >> http.enable_post_connection_check = true >> if options[:ssl_verify] == false >> http.verify_mode = OpenSSL::SSL::VERIFY_NONE >> else >> http.verify_mode = OpenSSL::SSL::VERIFY_PEER >> end >> store = OpenSSL::X509::Store.new >> store.set_default_paths >> http.cert_store = store >> end >> >> run it like this: >> >> open("https://someurl", :ssl_verify => false) {|f| >> print f.read >> >> } > > > Sorry, this all goes in open-uri.rb in your ruby base dir, eg: > > /usr/lib/ruby/1.8/open-uri.rb > or > /opt/local/lib/ruby/1.8/open-uri.rb > > or wherever it may be on your distro. The nice thing about Ruby is that if you don't want to modify your system files (for example I don't like to do it because it's quite hard to track later), then you can simply patch the modules/classes in question on the fly, at the beginning of your application. And possibly file a bug report (: However, I guess the verification-enabling code would be more versatile this way: if options[:ssl_verify] http.verify_mode = OpenSSL::SSL::VERIFY_PEER else http.verify_mode = OpenSSL::SSL::VERIFY_NONE end mortee