Skip to content

client_cert_path sends only the leaf certificate on mTLS #91

Description

@RamyaSaba

Question

Can this project provide a fix so that client_cert_path sends the full certificate chain (leaf + intermediate CA), not only the first PEM?
We use mTLS with certificates issued by an Intermediate CA (cert-manager / Kubernetes TLS secret):

  • tls.crt = leaf, then intermediate(s)
  • tls.key = leaf private key
  • ca.crt = Root CA only
    The HTTP server trusts the Root only. For the handshake to succeed, the client needs to present the Intermediate as well.

What happens today

client_cert_path is loaded here:
https://github.com/fluent-plugins-nursery/fluent-plugin-out-http/blob/v1.3.5/lib/fluent/plugin/out_http.rb

opts[:cert] = OpenSSL::X509::Certificate.new(File.read(@client_cert_path)) if File.file?(@client_cert_path)

That keeps only the first certificate in the file. When we point client_cert_path at a multi-PEM chain, mTLS to a Root-only server fails (unknown ca / certificate verify failed).

Observed on fluent-plugin-out-http 1.3.5. This plugin uses Net::HTTP directly (endpoint_url, client_cert_path). It is not Faraday, so http_backend typhoeus does not apply.

Will you provide a fix for this? If work is already planned, can you point us to the issue or target release so we can follow it?

Thanks.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions