Uploaded image for project: 'Undertow'
  1. Undertow
  2. UNDERTOW-2071

HTTPS client accepts certificates with wrong host

    XMLWordPrintable

Details

    • Bug
    • Resolution: Duplicate
    • Major
    • None
    • 2.2.14.Final
    • Core
    • None
    • Hide

      Create an Undertow client, and connect to https://wrong.host.badssl.com/ and retrieve its main page with default SSL settings. It should fail, but it succeeds.

      Show
      Create an Undertow client, and connect to https://wrong.host.badssl.com/ and retrieve its main page with default SSL settings. It should fail, but it succeeds.

    Description

      Using the Undertow HTTPS client to connect to a server with an SSL certificate that does not match the server's host, succeeds even though it shouldn't.

      Attachments

        Issue Links

          Activity

            People

              ropalka Richard Opalka
              somni451 new acct (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: