fix(tunnel): recover an expired leaf over plain HTTPS, not mTLS

Correction to the previous commit. Its recovery vhost could not work: nginx
will not forward an expired client certificate in ANY `ssl_verify_client` mode.
`optional` answers a bare `400 The SSL certificate error` before any location
runs, and `optional_no_ca` only tolerates CHAIN failures — see nginx's
`ngx_ssl_verify_error_optional()`, which covers self-signed / unknown-issuer /
unverifiable-leaf and NOT `X509_V_ERR_CERT_HAS_EXPIRED`. Verified live against
the deployed :8472 server, which rejected the real expired leaf.

So recovery drops mTLS instead of trying to bend it:

- agent: `buildTlsOptions` and the mTLS renew transport go back to being
  strictly fail-closed on expiry — the relaxation is gone from the TLS layer
  entirely. The rotator now decides per attempt: valid → mTLS `/renew`,
  expired-inside-grace → plain `/recover`, expired-beyond-grace → terminal
  `onExhausted` with no request issued at all.
- new `recoverCert` POSTs `{cert, csr}` with no client certificate. Possession
  of the private key is still proven: the CSR is self-signed by it and the host
  signer already enforces CSR PoP plus `CSR key == registered key`, so a
  replayed (public) cert without the key yields at most a certificate the
  attacker cannot authenticate with.
- control-plane: `/renew` is strict again (grace 0, matching the terminator).
  The grace lives on the new `POST /recover`, which reads the cert from the BODY
  and ignores the `x-client-cert` header, then runs the identical trust
  pipeline: X.509 path validation to the frp-client-CA anchors, SPIFFE parse,
  `notBefore` (never graced), registry `active` + account match. Revocation
  still bites.
- deploy: no new vhost, no new SNI, no DNS. One `location = /recover` merged
  into the existing enroll vhost, documented in
  `deploy/nginx/enroll-recover-location.md` with the nginx source citation.

The load-bearing new test is "a self-signed cert with a FORGED SPIFFE SAN is
refused → 401": nginx no longer validates the chain on this path, so that
assertion is what keeps `/recover` from being a cert vending machine.

Verified: agent 289/289, control-plane 290/290, tsc clean on both.
This commit is contained in:
Yaojia Wang
2026-07-29 09:52:17 +02:00
parent f3f4d8baa6
commit 5509c81eee
13 changed files with 559 additions and 472 deletions

View File

@@ -27,10 +27,7 @@ import {
type MtlsRequest,
} from '../src/certs/nativeRenew.js'
import { FakeTimer } from './fixtures/fakes.js'
import {
CertExpiredBeyondGraceError,
DEFAULT_EXPIRED_RENEW_GRACE_MS,
} from '../src/transport/dial.js'
import { CertExpiredBeyondGraceError } from '../src/certs/rotation.js'
const CFG: AgentConfig = {
relayUrl: 'wss://relay/agent',
@@ -296,38 +293,26 @@ describe('startNativeAutoRenew (A5 end-to-end)', () => {
})
/**
* Expired-leaf recovery. `createMtlsFetch` is the ONE place that decides whether a lapsed leaf may
* still be presented; if it keeps refusing (the pre-fix behaviour) the renewal can never leave the
* host and the tunnel stays dead until a manual re-pair.
* The mTLS renew transport stays STRICT about expiry: nginx refuses to forward an expired client
* cert at all, so an expired leaf must be routed to the plain `/recover` endpoint by the rotator
* rather than smuggled through this transport.
*/
describe('createMtlsFetch expired-leaf recovery', () => {
const expiredBy = (ms: number) => () => ({ validTo: new Date(Date.now() - ms) })
const DAY = 86_400_000
it('still presents a leaf that expired INSIDE the grace window (renewal can go out)', async () => {
describe('createMtlsFetch stays fail-closed on an expired leaf', () => {
it('refuses to present a lapsed leaf (recovery is the rotator\'s job, not this transport\'s)', async () => {
const { dir, ks } = enrolledKs()
let presented = ''
const request: MtlsRequest = async (_url, tls) => {
presented = tls.cert
let called = 0
const request: MtlsRequest = async () => {
called += 1
return { status: 201, body: '{}' }
}
const f = createMtlsFetch(ks, { request, certParser: expiredBy(8 * DAY) })
const res = await f('https://recover.example.com/renew', { method: 'POST', body: '{}' })
expect(res.status).toBe(201)
expect(presented).toBe('LEAFCERT')
rmSync(dir, { recursive: true, force: true })
})
it('refuses once the leaf is BEYOND the grace window (terminal — re-pair required)', async () => {
const { dir, ks } = enrolledKs()
const request: MtlsRequest = async () => ({ status: 201, body: '{}' })
const f = createMtlsFetch(ks, {
request,
certParser: expiredBy(DEFAULT_EXPIRED_RENEW_GRACE_MS + DAY),
certParser: () => ({ validTo: new Date(Date.now() - 86_400_000) }),
})
await expect(f('https://recover.example.com/renew', { method: 'POST' })).rejects.toThrow(
CertExpiredBeyondGraceError,
await expect(f('https://cp.example.com/renew', { method: 'POST' })).rejects.toThrow(
/expired/i,
)
expect(called).toBe(0)
rmSync(dir, { recursive: true, force: true })
})
})