Browse Source

tls: Use SHA1 for sessionIdContext in FIPS mode

FIPS 140-2 disallows use of MD5, which is used to derive the
default sessionIdContext for tls.createServer().

PR-URL: https://github.com/nodejs/node/pull/3755
Reviewed-By: Fedor Indutny <fedor@indutny.com>
process-exit-stdio-flushing
Stefan Budeanu 9 years ago
committed by Fedor Indutny
parent
commit
424ae5d4ac
  1. 3
      doc/api/tls.markdown
  2. 19
      lib/_tls_wrap.js

3
doc/api/tls.markdown

@ -842,7 +842,8 @@ automatically set as a listener for the [secureConnection][] event. The
- `sessionIdContext`: A string containing an opaque identifier for session - `sessionIdContext`: A string containing an opaque identifier for session
resumption. If `requestCert` is `true`, the default is MD5 hash value resumption. If `requestCert` is `true`, the default is MD5 hash value
generated from command-line. Otherwise, the default is not provided. generated from command-line. (In FIPS mode a truncated SHA1 hash is
used instead.) Otherwise, the default is not provided.
- `secureProtocol`: The SSL method to use, e.g. `SSLv3_method` to force - `secureProtocol`: The SSL method to use, e.g. `SSLv3_method` to force
SSL version 3. The possible values depend on your installation of SSL version 3. The possible values depend on your installation of

19
lib/_tls_wrap.js

@ -14,6 +14,21 @@ const Timer = process.binding('timer_wrap').Timer;
const tls_wrap = process.binding('tls_wrap'); const tls_wrap = process.binding('tls_wrap');
const TCP = process.binding('tcp_wrap').TCP; const TCP = process.binding('tcp_wrap').TCP;
const Pipe = process.binding('pipe_wrap').Pipe; const Pipe = process.binding('pipe_wrap').Pipe;
const defaultSessionIdContext = getDefaultSessionIdContext();
function getDefaultSessionIdContext() {
var defaultText = process.argv.join(' ');
/* SSL_MAX_SID_CTX_LENGTH is 128 bits */
if (process.config.variables.openssl_fips) {
return crypto.createHash('sha1')
.update(defaultText)
.digest('hex').slice(0, 32);
} else {
return crypto.createHash('md5')
.update(defaultText)
.digest('hex');
}
}
function onhandshakestart() { function onhandshakestart() {
debug('onhandshakestart'); debug('onhandshakestart');
@ -893,9 +908,7 @@ Server.prototype.setOptions = function(options) {
if (options.sessionIdContext) { if (options.sessionIdContext) {
this.sessionIdContext = options.sessionIdContext; this.sessionIdContext = options.sessionIdContext;
} else { } else {
this.sessionIdContext = crypto.createHash('md5') this.sessionIdContext = defaultSessionIdContext;
.update(process.argv.join(' '))
.digest('hex');
} }
}; };

Loading…
Cancel
Save