Repository navigation
.getPeerCertificate() on https.request() #7672
Description
Activity
- addedhttpsIssues and PRs related to the https subsystem.Issues and PRs related to the https subsystem.
on Jul 12, 2016 Maybe other tlsSocket fields are affected.
- addedtlsIssues and PRs related to the tls subsystem.Issues and PRs related to the tls subsystem.
on Jul 12, 2016 That is an unfortunate side effect of TLS session resumption. In your example, the first connection does a full TLS handshake but subsequent connections do an abridged version based on the previously established TLS session (which persists across connections.)
It's good for performance reasons (it cuts the number of TCP round-trips in half) but it loses the TLS connection metadata.
The reason it works as you expect it to with
{ agent: false }is that it creates a new session for every connection.Reacted by Juler SepnioThanks,
It depends the way you want to provide the application's subsystem. It doesn't really matter to me but the question is: is it a normal behaviour for a normal guy I would say :)
Actually the agent is something transparent (almost opaque) for the famous normal guy, no?Cheers
Michael- addeddocIssues and PRs related to Node.js documentation.Issues and PRs related to Node.js documentation.
on Jul 12, 2016 cc @nodejs/documentation - the documentation for getPeerCertificate() and the HTTPS agent should clarify that resumed sessions lack the peer's certificate info.
@mykiimike You're welcome to submit a PR too, of course. :-)
Reacted by Mik13, Philipp Haidenbauer, Ben Turner and kotiwoI will try to find some free time to do it 👍
Reacted by Mik13 and Philipp HaidenbauerA PR would be welcome.
This issue has been inactive for sufficiently long that it seems like perhaps it should be closed. Feel free to re-open (or leave a comment requesting that it be re-opened) if you disagree. I'm just tidying up and not acting on a super-strong opinion or anything like that.
Hi
.getPeerCertificate() does not returned fingerprint after first https.request(). It seems to be a problem with https.agent. If i set agent to false during https.request(opts) then i got correctly the fingerprint at each time.
Here is an example: