Skip to content

Puma does not load a CA when verification mode is set to :peer #1222

Description

@seanmckinley

Steps to reproduce

  1. Configure Puma to accept SSL connections:
key =  File.expand_path "./certs/my_key.key"
cert = File.expand_path "./certs/my_cert.crt"
ca = File.expand_path "./certs/my_ca.crt"

ssl_bind "0.0.0.0", 9292, :ca => ca, :cert => cert, :key => key, :verify_mode => :peer
  1. Start Puma, and get the following:
 starting in single mode...
* Version 3.6.2 (ruby 2.3.1-p112), codename: Sleepy Sunday Serenity
* Min threads: 5, max threads: 5
* Environment: production
ERROR: Please specify the SSL ca via 'ca='

Expected behavior

Puma should just start and accept TLS connections.

Actual behavior

Puma exits 1, requesting a CA be specified.

Why it's happening

If mode is set to verify a peer, it requests a CA:

if ['peer', 'force_peer'].include?(params['verify_mode'])

However, the ssl bind method will not attach a CA param to the URL it generates:
https://github.com/puma/puma/blob/master/lib/puma/dsl.rb#L273

If this is a bug and not just me being dumb/wrong, I have no problem submitting a PR to fix it.

System configuration

Ruby version: ruby 2.3.1p112 (2016-04-26 revision 54768)
Rails version: rails (5.0.1)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions