From: dusty Date: 2007-11-06T23:30:20+09:00 Subject: Re: open-uri + OpenSSL On Nov 5, 11:34 pm, mortee wrote: > dusty wrote: > > On Nov 5, 8:51 pm, dusty wrote: > >> On Oct 27, 12:26 pm, Matthew Lagace wrote: > > >>> Ok when I do that, it says: > >>> ssl value changed, but session already started > >>> dusty wrote: > >>>> On Oct 27, 1:35 am, Matthew Lagace wrote: > >>>>> Hello, > >>>>> I am usring open-uri to open an https:// link and when it tries to read > >>>>> it, I get the 'connect' : certificate verify failed error. How can I > >>>>> bypass this SSL verification? > >>>>> Thanks, > >>>>> M > >>>>> -- > >>>>> Posted viahttp://www.ruby-forum.com/. > >>>> Set the verify_mode to OpenSSL::SSL::VERIFY_NONE > >>>> eg: > >>>> http = Net::HTTP.new(host,port) > >>>> http.use_ssl = true > >>>> http.verify_mode = OpenSSL::SSL::VERIFY_NONE > >>> -- > >>> Posted viahttp://www.ruby-forum.com/. > >> Sorry, I guess you can't do it with open-uri. Here is a patch: > > >> add this ssl_verify option to the top of the file. > > >> FROM: > > >> module OpenURI > >> Options = { > >> :proxy => true, > >> :progress_proc => true, > >> :content_length_proc => true, > >> :http_basic_authentication => true, > >> } > > >> TO: > > >> module OpenURI > >> Options = { > >> :proxy => true, > >> :progress_proc => true, > >> :content_length_proc => true, > >> :http_basic_authentication => true, > >> :ssl_verify => true > >> } > > >> Change the part where it enables verification > > >> FROM: > > >> if target.class == URI::HTTPS > >> require 'net/https' > >> http.use_ssl = true > >> http.enable_post_connection_check = true > >> http.verify_mode = OpenSSL::SSL::VERIFY_PEER > >> store = OpenSSL::X509::Store.new > >> store.set_default_paths > >> http.cert_store = store > >> end > > >> TO: > >> if target.class == URI::HTTPS > >> require 'net/https' > >> http.use_ssl = true > >> http.enable_post_connection_check = true > >> if options[:ssl_verify] == false > >> http.verify_mode = OpenSSL::SSL::VERIFY_NONE > >> else > >> http.verify_mode = OpenSSL::SSL::VERIFY_PEER > >> end > >> store = OpenSSL::X509::Store.new > >> store.set_default_paths > >> http.cert_store = store > >> end > > >> run it like this: > > >> open("https://someurl", :ssl_verify => false) {|f| > >> print f.read > > >> } > > > Sorry, this all goes in open-uri.rb in your ruby base dir, eg: > > > /usr/lib/ruby/1.8/open-uri.rb > > or > > /opt/local/lib/ruby/1.8/open-uri.rb > > > or wherever it may be on your distro. > > The nice thing about Ruby is that if you don't want to modify your > system files (for example I don't like to do it because it's quite hard > to track later), then you can simply patch the modules/classes in > question on the fly, at the beginning of your application. And possibly > file a bug report (: > > However, I guess the verification-enabling code would be more versatile > this way: > > if options[:ssl_verify] > http.verify_mode = OpenSSL::SSL::VERIFY_PEER > else > http.verify_mode = OpenSSL::SSL::VERIFY_NONE > end > > mortee Good idea. I submitted a patch to rubyforge. This might be useful and simple enough to add. http://rubyforge.org/tracker/?group_id=426&atid=1698&func=detail&aid=15390