Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 568657

Summary: SSL: unhandled exception error when wrong hostname
Product: Red Hat Enterprise MRG Reporter: Jan Sarenik <jsarenik>
Component: qpid-cppAssignee: Gordon Sim <gsim>
Status: CLOSED ERRATA QA Contact: Jan Sarenik <jsarenik>
Severity: low Docs Contact:
Priority: high    
Version: DevelopmentCC: gsim
Target Milestone: 1.3   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
Reproduction/verification script none

Description Jan Sarenik 2010-02-26 09:38:06 UTC
This is low priority, can be moved into 1.4.

While testing https://bugzilla.redhat.com/show_bug.cgi?id=533045
I found that with wrong hostname the resulting message produced
by qpidd is

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
error IO worker thread exiting with unhandled exception: Success (qpid/sys/ssl/SslIo.cpp:386)    
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

and that is not very descriptive. I would expect it to say something
like "SSL connection error (possible wrong hostname)" because this
happens when client tries to establish a connection to broker but
is using hostname which is not defined in CN of broker's certificate.
(See the script included in abovementioned bug for more details.)

Comment 1 Jan Sarenik 2010-02-26 11:46:43 UTC
The more important thing I forgot to mention is
that the client hangs after writing that message.

On RHEL5 x86_64 and qpid-cpp-server-ssl-0.7.908272-1.el5:
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 
# pstack `pgrep perftest`
#0  0x00000036be20ad09 in pthread_cond_wait@@GLIBC_2.3.2 ()
#1  0x00002ac46aa215d1 in qpid::client::StateManager::waitFor ()
#2  0x00002ac46a9d6f71 in qpid::client::ConnectionHandler::waitForOpen ()
#3  0x00002ac46a9e5c7f in qpid::client::ConnectionImpl::open ()
#4  0x00002ac46a9d557d in qpid::client::Connection::open ()
#5  0x0000000000413c87 in ?? ()
#6  0x000000000040bd32 in __cxa_pure_virtual ()
#7  0x00000036bda1d994 in __libc_start_main () from /lib64/libc.so.6
#8  0x000000000040aa69 in __cxa_pure_virtual ()
#9  0x00007fffa836b088 in ?? ()
#10 0x0000000000000000 in ?? ()
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Comment 2 Andrew Stitcher 2010-04-28 04:15:25 UTC
The error message that is being seen here is a "catch all" error message - it indicates thatt there is no code that is handling this error specifically and the exception is not being caught anywhere.

A seemingly odd feature here is that there is clearly no failing system call since errno must be 0. This would be consistent with the error being from NSS and the resultant exception not being caught.

Comment 3 Gordon Sim 2010-04-28 15:28:28 UTC
Fixed in r938992.

Comment 4 Jan Sarenik 2010-05-26 07:17:54 UTC
VERIFIED, the message is now
------------------
Failed: Unable to communicate securely with peer: requested domain name does not match the server's certificate. [-12276] (qpid/sys/ssl/SslSocket.cpp:182)
------------------
and the client shuts down (does not wait there).

Tested on qpid-cpp-server-ssl-0.7.946106-1.el5

Comment 5 Jan Sarenik 2010-05-26 08:06:50 UTC
Created attachment 416708 [details]
Reproduction/verification script