Permalink
Browse files
tls: emit a warning when servername is an IP address
Setting the TLS ServerName to an IP address is not permitted by RFC6066. This will be ignored in a future version. Refs: #18127 PR-URL: #23329 Fixes: #18071 Reviewed-By: James M Snell <jasnell@gmail.com> Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Trivikram Kamat <trivikr.dev@gmail.com> Reviewed-By: Sakthipriyan Vairamani <thechargingvolcano@gmail.com>
- Loading branch information...
Showing
with
69 additions
and 1 deletion.
- +15 −0 doc/api/deprecations.md
- +13 −1 lib/_tls_wrap.js
- +41 −0 test/parallel/test-tls-ip-servername-deprecation.js
| @@ -0,0 +1,41 @@ | |||
| 'use strict'; | |||
|
|
|||
| const common = require('../common'); | |||
| const fixtures = require('../common/fixtures'); | |||
|
|
|||
| if (!common.hasCrypto) | |||
| common.skip('missing crypto'); | |||
|
|
|||
| const tls = require('tls'); | |||
|
|
|||
| // This test expects `tls.connect()` to emit a warning when | |||
| // `servername` of options is an IP address. | |||
| common.expectWarning( | |||
| 'DeprecationWarning', | |||
| 'Setting the TLS ServerName to an IP address is not permitted by ' + | |||
| 'RFC 6066. This will be ignored in a future version.', | |||
| 'DEP0123' | |||
| ); | |||
|
|
|||
| { | |||
| const options = { | |||
| key: fixtures.readKey('agent1-key.pem'), | |||
| cert: fixtures.readKey('agent1-cert.pem') | |||
| }; | |||
|
|
|||
| const server = tls.createServer(options, function(s) { | |||
| s.end('hello'); | |||
| }).listen(0, function() { | |||
| const client = tls.connect({ | |||
| port: this.address().port, | |||
| rejectUnauthorized: false, | |||
| servername: '127.0.0.1', | |||
| }, function() { | |||
| client.end(); | |||
| }); | |||
| }); | |||
|
|
|||
| server.on('connection', common.mustCall(function(socket) { | |||
| server.close(); | |||
| })); | |||
| } | |||
This should have been a link to #23329, shouldn't it?