Skip to content

fix: disable self-signed hub certificates in BACnet/SC websocket clients by default - #1434

Merged
skarg merged 7 commits into
masterfrom
bugfix/bacnet-sc-always-accepts-self-signed-hub-cert
Jul 22, 2026
Merged

skarg merged 7 commits into
masterfrom
bugfix/bacnet-sc-always-accepts-self-signed-hub-cert

Conversation

@skarg

@skarg skarg commented Jul 21, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adjusts BACnet/SC websocket client TLS behavior to be secure-by-default by disabling acceptance of self-signed hub certificates (and skipping hostname verification) unless explicitly enabled via configuration.

Changes:

  • Introduces BSC_CONF_WEBSOCKET_SELFSIGNED_ENABLED (default 0) in bsc-conf.h.
  • Gates LCCSCF_ALLOW_SELFSIGNED and LCCSCF_SKIP_SERVER_CERT_HOSTNAME_CHECK behind the new config macro on Win32/Linux/BSD websocket clients.
  • Leaves standard TLS (LCCSCF_USE_SSL) as the default client behavior.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

File Description
src/bacnet/datalink/bsc/bsc-conf.h Adds a new compile-time config toggle to control permissive TLS behavior for websocket clients.
ports/win32/websocket-cli.c Uses the new config toggle to control whether self-signed + hostname-skip flags are enabled.
ports/linux/websocket-cli.c Uses the new config toggle to control whether self-signed + hostname-skip flags are enabled.
ports/bsd/websocket-cli.c Uses the new config toggle to control whether self-signed + hostname-skip flags are enabled.

Comment thread src/bacnet/datalink/bsc/bsc-conf.h Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 10 out of 12 changed files in this pull request and generated 3 comments.

Comment thread ports/linux/websocket-cli.c
Comment thread ports/bsd/websocket-cli.c
Comment thread ports/win32/websocket-cli.c
@skarg
skarg merged commit ffe32bb into master Jul 22, 2026
36 checks passed
@skarg
skarg deleted the bugfix/bacnet-sc-always-accepts-self-signed-hub-cert branch July 22, 2026 10:26
skarg added a commit that referenced this pull request Aug 4, 2026
* doc: add CVE-2026-64675 to GHSA-mmg6-p4pr-cj6h advisory entry

The published advisory for GHSA-mmg6-p4pr-cj6h (pre-auth OOB read in
xy_color_decode) was assigned CVE-2026-64675, but the SECURITY.md
entry was missing the CVE link. Add it to match the published record.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* doc: add 9 draft advisory entries to SECURITY.md

Add entries for all draft GHSA advisories visible after authentication:

- GHSA-f23j-5f4w-cxhj: Command object action list resize heap use-after-free write (1.7.0-rc2, PR #1461)
- GHSA-rxvq-3mhq-474x: Cross-peer disclosure caused by a BVLC length mismatch (1.4.6/1.5.2/1.6.1/1.7.0, PR #1451)
- GHSA-9qx8-hr5x-r35c: Silent decode failure in bacnet_octet_string_decode() (1.4.6/1.5.2/1.6.1/1.7.0, PR #1440)
- GHSA-gv7j-28x8-cr37: AtomicWriteFile access-method mismatch leading to RAMFS heap OOB read (1.4.6/1.5.2/1.6.1/1.7.0, PR #1439)
- GHSA-gj7v-fwjp-7x8q: Router route-table Tx_Buffer overflow (1.4.6/1.5.2/1.6.1/1.7.0, PR #1438)
- GHSA-hg85-pmm3-jfcf: Structured View subordinate-list[0] unbounded resize DoS (1.6.1/1.7.0, PR #1437)
- GHSA-92q2-p4vr-fvmp: BACnet/SC hub never requires a client cert (1.4.6/1.5.2/1.6.1/1.7.0, PR #1436)
- GHSA-gr74-333w-7wg8: Trailing MORE bit BACnet/SC header option OOB read/write (1.4.6/1.5.2/1.6.1/1.7.0, PR #1435)
- GHSA-jgm4-2wg9-jwfg: BACnet/SC node accepts self-signed hub cert MITM (1.4.6/1.5.2/1.6.1/1.7.0, PR #1434)

None of these drafts have CVE IDs assigned yet.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
skarg added a commit that referenced this pull request Aug 11, 2026
…nts by default (#1434)

* fix: enable support for self-signed server certificates in BACnet/SC clients by using a single runtime setter, disabled by default.

* add: BACNET_SC_SELFSIGNED_ENABLED environment variable for example apps
skarg added a commit that referenced this pull request Aug 11, 2026
…nts by default (#1434)

* fix: enable support for self-signed server certificates in BACnet/SC clients by using a single runtime setter, disabled by default.

* add: BACNET_SC_SELFSIGNED_ENABLED environment variable for example apps
skarg added a commit that referenced this pull request Aug 13, 2026
…nts by default (#1434)

* fix: enable support for self-signed server certificates in BACnet/SC clients by using a single runtime setter, disabled by default.

* add: BACNET_SC_SELFSIGNED_ENABLED environment variable for example apps

(cherry picked from commit ffe32bb)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants