fix(tunnel): recover an expired leaf over plain HTTPS, not mTLS
Correction to the previous commit. Its recovery vhost could not work: nginx
will not forward an expired client certificate in ANY `ssl_verify_client` mode.
`optional` answers a bare `400 The SSL certificate error` before any location
runs, and `optional_no_ca` only tolerates CHAIN failures — see nginx's
`ngx_ssl_verify_error_optional()`, which covers self-signed / unknown-issuer /
unverifiable-leaf and NOT `X509_V_ERR_CERT_HAS_EXPIRED`. Verified live against
the deployed :8472 server, which rejected the real expired leaf.
So recovery drops mTLS instead of trying to bend it:
- agent: `buildTlsOptions` and the mTLS renew transport go back to being
strictly fail-closed on expiry — the relaxation is gone from the TLS layer
entirely. The rotator now decides per attempt: valid → mTLS `/renew`,
expired-inside-grace → plain `/recover`, expired-beyond-grace → terminal
`onExhausted` with no request issued at all.
- new `recoverCert` POSTs `{cert, csr}` with no client certificate. Possession
of the private key is still proven: the CSR is self-signed by it and the host
signer already enforces CSR PoP plus `CSR key == registered key`, so a
replayed (public) cert without the key yields at most a certificate the
attacker cannot authenticate with.
- control-plane: `/renew` is strict again (grace 0, matching the terminator).
The grace lives on the new `POST /recover`, which reads the cert from the BODY
and ignores the `x-client-cert` header, then runs the identical trust
pipeline: X.509 path validation to the frp-client-CA anchors, SPIFFE parse,
`notBefore` (never graced), registry `active` + account match. Revocation
still bites.
- deploy: no new vhost, no new SNI, no DNS. One `location = /recover` merged
into the existing enroll vhost, documented in
`deploy/nginx/enroll-recover-location.md` with the nginx source citation.
The load-bearing new test is "a self-signed cert with a FORGED SPIFFE SAN is
refused → 401": nginx no longer validates the chain on this path, so that
assertion is what keeps `/recover` from being a cert vending machine.
Verified: agent 289/289, control-plane 290/290, tsc clean on both.
This commit is contained in:
@@ -27,10 +27,7 @@ import {
|
||||
type MtlsRequest,
|
||||
} from '../src/certs/nativeRenew.js'
|
||||
import { FakeTimer } from './fixtures/fakes.js'
|
||||
import {
|
||||
CertExpiredBeyondGraceError,
|
||||
DEFAULT_EXPIRED_RENEW_GRACE_MS,
|
||||
} from '../src/transport/dial.js'
|
||||
import { CertExpiredBeyondGraceError } from '../src/certs/rotation.js'
|
||||
|
||||
const CFG: AgentConfig = {
|
||||
relayUrl: 'wss://relay/agent',
|
||||
@@ -296,38 +293,26 @@ describe('startNativeAutoRenew (A5 end-to-end)', () => {
|
||||
})
|
||||
|
||||
/**
|
||||
* Expired-leaf recovery. `createMtlsFetch` is the ONE place that decides whether a lapsed leaf may
|
||||
* still be presented; if it keeps refusing (the pre-fix behaviour) the renewal can never leave the
|
||||
* host and the tunnel stays dead until a manual re-pair.
|
||||
* The mTLS renew transport stays STRICT about expiry: nginx refuses to forward an expired client
|
||||
* cert at all, so an expired leaf must be routed to the plain `/recover` endpoint by the rotator
|
||||
* rather than smuggled through this transport.
|
||||
*/
|
||||
describe('createMtlsFetch expired-leaf recovery', () => {
|
||||
const expiredBy = (ms: number) => () => ({ validTo: new Date(Date.now() - ms) })
|
||||
const DAY = 86_400_000
|
||||
|
||||
it('still presents a leaf that expired INSIDE the grace window (renewal can go out)', async () => {
|
||||
describe('createMtlsFetch stays fail-closed on an expired leaf', () => {
|
||||
it('refuses to present a lapsed leaf (recovery is the rotator\'s job, not this transport\'s)', async () => {
|
||||
const { dir, ks } = enrolledKs()
|
||||
let presented = ''
|
||||
const request: MtlsRequest = async (_url, tls) => {
|
||||
presented = tls.cert
|
||||
let called = 0
|
||||
const request: MtlsRequest = async () => {
|
||||
called += 1
|
||||
return { status: 201, body: '{}' }
|
||||
}
|
||||
const f = createMtlsFetch(ks, { request, certParser: expiredBy(8 * DAY) })
|
||||
const res = await f('https://recover.example.com/renew', { method: 'POST', body: '{}' })
|
||||
expect(res.status).toBe(201)
|
||||
expect(presented).toBe('LEAFCERT')
|
||||
rmSync(dir, { recursive: true, force: true })
|
||||
})
|
||||
|
||||
it('refuses once the leaf is BEYOND the grace window (terminal — re-pair required)', async () => {
|
||||
const { dir, ks } = enrolledKs()
|
||||
const request: MtlsRequest = async () => ({ status: 201, body: '{}' })
|
||||
const f = createMtlsFetch(ks, {
|
||||
request,
|
||||
certParser: expiredBy(DEFAULT_EXPIRED_RENEW_GRACE_MS + DAY),
|
||||
certParser: () => ({ validTo: new Date(Date.now() - 86_400_000) }),
|
||||
})
|
||||
await expect(f('https://recover.example.com/renew', { method: 'POST' })).rejects.toThrow(
|
||||
CertExpiredBeyondGraceError,
|
||||
await expect(f('https://cp.example.com/renew', { method: 'POST' })).rejects.toThrow(
|
||||
/expired/i,
|
||||
)
|
||||
expect(called).toBe(0)
|
||||
rmSync(dir, { recursive: true, force: true })
|
||||
})
|
||||
})
|
||||
|
||||
Reference in New Issue
Block a user