Skip to content

xds: Keep saved certs and roots after SslContext update - #13085

Draft
Nicolas-EM wants to merge 1 commit into
grpc:masterfrom
Nicolas-EM:nem/fix-13058
Draft

Nicolas-EM wants to merge 1 commit into
grpc:masterfrom
Nicolas-EM:nem/fix-13058

Conversation

@Nicolas-EM

Copy link
Copy Markdown

Fixes #13058.

CertProviderSslContextProvider cleared the saved key, cert chain and trusted roots after every SslContext build (clearKeysAndCerts()). When the identity cert and the CA roots come from separate certificate provider instances (for example, two file_watcher instances with different refresh intervals), the roots provider usually does not send another update. The next identity cert rotation then found no roots and did not rebuild the SslContext, so new connections kept the old, possibly expired, identity cert. The same problem occurred with a single shared provider instance when only the identity cert changed.

This change removes clearKeysAndCerts(). The saved identity credentials and trust roots are now kept as the latest known values. An update from either provider rebuilds the SslContext with the latest values from both, as discussed in the issue. This generalizes #12340, which kept the roots only when using system root certs.

Behavior changes:

  • A root-only update now rebuilds the SslContext. Before, it did not, because the key had been cleared.
  • When a shared provider instance updates the cert and the roots in the same refresh, the SslContext is built twice. The first build briefly uses the new identity cert with the old roots. The next update immediately replaces it.

Tests:

  • Updated the existing client and server tests for the new behavior, and removed assertions on the internal saved* fields after a build.
  • Added client and server tests for separate cert and root instances: cert-only updates, root-only updates, and updates that the other instance must ignore.
  • Added client and server tests for a shared instance with cert-only updates.
  • The new *UpdateOnly tests fail without the change in CertProviderSslContextProvider.

Fixes grpc#13058.

CertProviderSslContextProvider cleared the saved key, cert chain and
trusted roots after every SslContext build. When the identity cert and
the CA roots come from separate certificate provider instances, the
roots provider usually does not send another update, so the next
identity cert rotation found no roots and did not rebuild the
SslContext. New connections kept the old, possibly expired, identity
cert. The same problem occurred with a single shared provider instance
when only the identity cert changed.

The saved identity credentials and trust roots are now kept as the
latest known values. An update from either provider rebuilds the
SslContext with the latest values from both. This generalizes the fix
in grpc#12340, which kept the roots only when using system root certs.

As a result, a root-only update now also rebuilds the SslContext. When
a shared provider instance updates the cert and the roots in the same
refresh, the SslContext is built twice, and the first build briefly
uses the new identity cert with the old roots.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

xDS: identity cert never refreshes when the CA root provider is a separate file_watcher instance

1 participant