doc: fix broken TLS security level example - #65391
Open
soreavis wants to merge 1 commit into
Open
Conversation
The example under "Setting security levels" does not run. The client sets `maxVersion: 'TLSv1'` while its `minVersion` stays at the `tls.DEFAULT_MIN_VERSION` default of `'TLSv1.2'`, so no version overlaps and the connection fails with ERR_SSL_NO_PROTOCOLS_AVAILABLE. Setting the client's `minVersion` is not enough on its own: the handshake then fails with an alert 40, because `createServer` is given no key or certificate and the server has no shared cipher. Set `minVersion` on the client, add the key and certificate placeholders and the openssl recipe that the other sections using them already carry, pass the server certificate as the client's `ca`, and use port 8000 like the rest of the file. The section now runs from an empty directory and prints "Client connected with protocol: TLSv1". Signed-off-by: Julian Soreavis <julian.soreavis@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The example under "Setting security levels" does not run. The client sets
maxVersion: 'TLSv1'while itsminVersionstays at thetls.DEFAULT_MIN_VERSIONdefault of'TLSv1.2', so no version overlaps and the connection fails withERR_SSL_NO_PROTOCOLS_AVAILABLE— the error @davidebombelli reported in #60569, having copied the snippet straight out of these docs. @pimterry said the behavior itself is correct and asked for a docs fix.Setting the client's
minVersion, the fix suggested on the issue, isn't enough on its own: the handshake then fails with an alert 40, becausecreateServeris given no key or certificate and the server has no shared cipher (ERR_SSL_NO_SHARED_CIPHER). This setsminVersionon the client, adds theserver-key.pem/server-cert.pemplaceholders and theopenssl reqrecipe that the other two sections using those placeholders already carry, passes the server certificate as the client'sca, and uses the port 8000 the rest of the file uses rather than 443.Verified on v26.7.0 (OpenSSL 3.6.3) from an empty directory: the section's recipe and both code blocks, extracted from this diff and run unmodified, print
Client connected with protocol: TLSv1. They still fail with either piece missing —ERR_SSL_NO_PROTOCOLS_AVAILABLEwithout the clientminVersion, alert 40 without the certificate. The snippet landed already missing both pieces, in 059f2f4 (July 2024).#60571 proposed adding a note describing the failure; per the follow-up on the issue the example itself should work, so this fixes the example instead.
I used an AI assistant while researching and drafting this change; I've verified the behavior with live repros and against the source myself and take full responsibility for it.
Fixes: #60569
Refs: #60571