Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added SSL cacert patch to support Corporate MITM Proxies #2570

Merged
merged 2 commits into from
May 28, 2021
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 19 additions & 1 deletion src/rebar_utils.erl
Original file line number Diff line number Diff line change
Expand Up @@ -1042,6 +1042,24 @@ ssl_opts(Url) ->
[{verify, verify_none}]
end.

%% @private Determines which CA Certs to use for the HTTPS request.
%% If the user sets the value {ssl_cacerts_path, "path to pem"} in their
%% global rebar.config file, the pem will be encoded and used for the
%% SSL connection. Otherwise, CA Certs from `certifi` will be used.
%% This functionality is useful (needed) for Corporate Proxies that rewrite Certs.
%% See ssl_opts/2
get_cacerts() ->
GlobalConfigFile = rebar_dir:global_config(),
Config = rebar_config:consult_file(GlobalConfigFile),
case proplists:get_value(ssl_cacerts_path, Config) of
undefined ->
certifi:cacerts();
Path ->
{ok, Bin} = file:read_file(Path),
Pems = public_key:pem_decode(Bin),
[Der || {'Certificate', Der, _} <- Pems]
end.

%%------------------------------------------------------------------------------
%% @doc
%% Return the SSL options adequate for the project based on
Expand All @@ -1058,7 +1076,7 @@ ssl_opts(ssl_verify_enabled, Url) ->
#{host := Hostname} = rebar_uri:parse(rebar_utils:to_list(Url)),
VerifyFun = {fun ssl_verify_hostname:verify_fun/3,
[{check_hostname, Hostname}]},
CACerts = certifi:cacerts(),
CACerts = get_cacerts(),
[{verify, verify_peer}, {depth, 2}, {cacerts, CACerts},
{partial_chain, fun partial_chain/1}, {verify_fun, VerifyFun}];
false ->
Expand Down