Repository navigation
Conversation
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 58 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (11)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe CLI now validates remote and local certificate chains for trust, hostname, dates, handshake signatures, and leaf revocation. It reports validation results in text, JSON, and the TUI while keeping invalid remote chains available for inspection. ChangesCertificate Chain Validation
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~60 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant CLI
participant cert_chain
participant TLSServer
participant ReportingServerCertVerifier
participant Verifier
participant revocationDownload
CLI->>cert_chain: Pass host, CA files, and CRL files
cert_chain->>TLSServer: Establish TLS connection
TLSServer->>ReportingServerCertVerifier: Provide certificate chain and handshake signature
ReportingServerCertVerifier->>Verifier: Check certificate path and handshake signature
cert_chain->>revocationDownload: Request CRLs when no CRL files were supplied
revocationDownload-->>cert_chain: Return downloaded CRLs or an error
cert_chain-->>CLI: Return certificates and validation report
Merge Risk: ⚪ Minimal · up to This increment only adds changelog entries describing the validation feature, so it has no runtime impact and is ready to merge. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Remote inspection now automatically retrieves revocation data from URLs in certificates whose chains are trusted. Those requests can reach services accessible from the inspecting machine without a destination restriction. Trust checks, request limits and offline local inspection narrow the exposure. Validation results remain advisory rather than enforcing certificate acceptance. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 49.49% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 99 functions across 10 files. (1 skipped: 1 unsupported.)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
96832da to
784a9a4
Compare
|
Rebased onto These are actual CLI outputs from the rebased build on macOS with system trust roots. The remote examples all exited with 0 and wrote their PEM dumps, including the invalid chains. Certificate field rows are omitted from the text excerpts below. Dump paths are shown relative to the output directory. $ inspect-cert-chain --host expired.badssl.com --timeout 30s --fields subject --dump expired.badssl.com.pem
Certificate chain: INVALID
Path validation: INVALID (certificate expired)
Hostname (expired.badssl.com): VALID
Certificate 1 dates: INVALID (expired)
Certificate 2 dates: VALID
Certificate 3 dates: INVALID (expired)
TLS handshake signature: VALID
Revocation (leaf): UNKNOWN (certificate path is invalid)$ inspect-cert-chain --host wrong.host.badssl.com --timeout 30s --fields subject --dump wrong.host.badssl.com.pem
Certificate chain: INVALID
Path validation: VALID
Hostname (wrong.host.badssl.com): INVALID (hostname does not match certificate names)
Certificate 1 dates: VALID
Certificate 2 dates: VALID
Certificate 3 dates: VALID
TLS handshake signature: VALID
Revocation (leaf): VALID$ inspect-cert-chain --host revoked.badssl.com --timeout 30s --fields subject --dump revoked.badssl.com.pem
Certificate chain: INVALID
Path validation: VALID
Hostname (revoked.badssl.com): VALID
Certificate 1 dates: VALID
Certificate 2 dates: VALID
Certificate 3 dates: VALID
Certificate 4 dates: VALID
TLS handshake signature: VALID
Revocation (leaf): INVALID (certificate revoked)$ inspect-cert-chain --host incomplete-chain.badssl.com --timeout 30s --fields subject --dump incomplete-chain.badssl.com.pem
Certificate chain: INVALID
Path validation: INVALID (missing issuer certificate or untrusted issuer)
Hostname (incomplete-chain.badssl.com): VALID
Certificate 1 dates: VALID
TLS handshake signature: VALID
Revocation (leaf): UNKNOWN (certificate path is invalid)$ inspect-cert-chain --host self-signed.badssl.com --timeout 30s --fields subject --dump self-signed.badssl.com.pem
Certificate chain: INVALID
Path validation: INVALID (self-issued certificate is not trusted)
Hostname (self-signed.badssl.com): VALID
Certificate 1 dates: VALID
TLS handshake signature: VALID
Revocation (leaf): UNKNOWN (certificate path is invalid)$ inspect-cert-chain --host untrusted-root.badssl.com --timeout 30s --fields subject --dump untrusted-root.badssl.com.pem
Certificate chain: INVALID
Path validation: INVALID (root CA is not trusted)
Hostname (untrusted-root.badssl.com): VALID
Certificate 1 dates: VALID
Certificate 2 dates: VALID
TLS handshake signature: VALID
Revocation (leaf): UNKNOWN (certificate path is invalid)$ inspect-cert-chain --host sha256.badssl.com --timeout 30s --fields subject --dump sha256.badssl.com.pem
Certificate chain: VALID
Path validation: VALID
Hostname (sha256.badssl.com): VALID
Certificate 1 dates: VALID
Certificate 2 dates: VALID
Certificate 3 dates: VALID
TLS handshake signature: VALID
Revocation (leaf): VALIDJSON output keeps field selection and adds a separate $ inspect-cert-chain --host wrong.host.badssl.com --timeout 30s --json --fields subject{
"certificates": [
{
"subject": "CN=*.badssl.com"
},
{
"subject": "CN=YR1,O=Let's Encrypt,C=US"
},
{
"subject": "CN=Root YR,O=ISRG,C=US"
}
],
"validation": {
"dates": [
{
"status": "valid"
},
{
"status": "valid"
},
{
"status": "valid"
}
],
"handshake_signature": {
"status": "valid"
},
"hostname": {
"name": "wrong.host.badssl.com",
"reason": "hostname does not match certificate names",
"status": "invalid"
},
"path": {
"status": "valid"
},
"revocation": {
"status": "valid"
},
"status": "invalid"
}
}Local validation of the saved valid chain exits with 0. Local revocation is $ inspect-cert-chain --file sha256.badssl.com.pem --check --hostname sha256.badssl.com --fields subject
OK: certificate 1: within validity period
OK: certificate 2: within validity period
OK: certificate 3: within validity period
OK: 3 certificates
Certificate chain: VALID
Path validation: VALID
Hostname (sha256.badssl.com): VALID
Certificate 1 dates: VALID
Certificate 2 dates: VALID
Certificate 3 dates: VALID
Revocation (leaf): NOT CHECKEDValidation: all 73 tests passed on macOS and Rust 1.93 Linux; all seven live BadSSL checks passed; the repository formatting and Clippy checks passed. |
784a9a4 to
c8b4045
Compare
c8b4045 to
64597d9
Compare
|
Reproducible real-site examples for the remote-validation layer at The key output lines below were verified by this commit's six passing live BadSSL checks when the stack was split. Fresh manual captures on 2026-10-08 encountered TLS connection resets/timeouts from this environment, so these are tested expected excerpts, not a fresh stdout capture. Build this PR: gh pr checkout 531
cargo build --locked
ICC="$PWD/target/debug/inspect-cert-chain"A valid control: "$ICC" --host sha256.badssl.com --timeout 30s --fields subjectA certificate for the wrong hostname: "$ICC" --host wrong.host.badssl.com --timeout 30s --fields subjectAn incomplete server chain: "$ICC" --host incomplete-chain.badssl.com --timeout 30s --fields subjectThe live tests verified exit code To repeat all six live assertions: just test-badsslThe excerpts omit other certificate and validation lines. Public endpoints and certificates can change. |
Remote inspection previously bypassed certificate validation. Apply the local-chain validator during the TLS handshake and show trust, hostname, date, and handshake-signature results in text, JSON, and interactive output.
Use the selected
--server-nameand allow custom CA files. Keep invalid certificates available for inspection and--dump. Preserve the fetch deadline and date-based--checkexit codes. Revocation remains not checked in this layer.This is layer 2 of 4, based on local validation. Includes TLS 1.2/1.3 coverage, invalid handshake signatures, JSON and timeout compatibility, and six live BadSSL checks.
Validation on macOS:
just test(77 passed),nix develop -c just check(formatting and Clippy passed), andjust test-badssl(6 passed).