Skip to content

VendorCA from SecurityArtifacts not added to ClientCAs pool in [server.go](http://_vscodecontentref_/0) v0.6.1 #140

Description

@khrasool

Problem
The bootz server v0.6.1 fails to validate client IDevID certificates during TLS handshake because the [VendorCA]certificate from SecurityArtifacts is never added to the [ClientCAs] pool.

Current Behavior

In [server.go] lines 117-119:

// In a real scenario, this cert pool would contain CA(s) that
// signed the device's IDevID cert.
vendorIDevIDPool := x509.NewCertPool()

The [vendorIDevIDPool] is created empty and never populated, even though [SecurityArtifacts.VendorCA] is available defined in [types.go].

Later at line 133, this empty pool is used:

ClientAuth: tls.VerifyClientCertIfGiven,
ClientCAs: vendorIDevIDPool,

Impact

Unary gRPC calls (GetBootstrapData, ReportStatus) that require IDevID cert validation fail with:
rpc error: code = Unavailable desc = connection error: desc = "error reading server preface: remote error: tls: unknown certificate authority"

Devices cannot bootstrap using Cisco SUDI certificates or other vendor-signed IDevID certs

Expected Behavior

The [VendorCA] should be added to the cert pool:

vendorIDevIDPool := x509.NewCertPool()
if sa.VendorCA != nil {
vendorIDevIDPool.AddCert(sa.VendorCA)
}

Environment

bootz version: v0.6.1
Platform: Cisco IOS-XR with ECC256 SUDI certificates
TLS version: 1.3

Reproduction

Configure bootz server with SecurityArtifacts containing a valid [VendorCA]
Device attempts unary RPC call with IDevID cert in TLS handshake
Server rejects with "unknown certificate authority"

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions