Files
geedge-jira/md/OMPUB-897.md

148 lines
5.3 KiB
Markdown
Raw Permalink Normal View History

2025-09-14 21:52:36 +00:00
# TSG版本为2211和2212的intercept功能证书替换存在问题
| ID | Creation Date | Assignee | Status |
|----|----------------|----------|--------|
| OMPUB-897 | 2023-04-12T14:52:36.000+0800 | 冯伟浩 | 已关闭 |
---
在TSG版本为22.11和22.12环境中进行测试
{color:#de350b}{color:#172b4d}22.11环境:{color}192.168.44.228{color}
{color:#de350b}{color:#172b4d}22.12环境:{color}192.168.44.29{color}
动作都是intercept,Source选择本机IP,Application选择SSL
Filter中选择SNI,FQDN的值为*.badssl.com
For trusted servers 配置文件保持不变
For untrusted servers 配置文件在Untrusted和Trusted Default进行切换
Decryption Profile 选择新建的配置文件开启Certificate Checks四个按钮Fail Action选择Pass-throughDynamic Bypass全部关闭Protocol Version全部开启
 
测试结果:
{color:#de350b}22.11环境{color}For untrusted servers选择Untrusted和Trusted Default配置文件后进行访问证书都是{color:#de350b}信任证书{color}
{color:#de350b}22.12环境{color}For untrusted servers选择Untrusted和Trusted Default配置文件后进行访问证书都是{color:#de350b}非信任证书{color}
 
{color:#172b4d}按照预期结果的话应该是For untrusted servers选择Untrusted配置文件后进行访问会提示非信任证书并显示非信任证书{color}
{color:#172b4d}For untrusted servers选择Trusted Default配置文件后进行访问会显示信任证书{color}
{color:#172b4d}请查看附件中的截图,并协助确认两个环境是否都存在问题?{color}**gitlab** commented on *2023-04-13T16:53:00.654+0800*:
[冯伟浩|https://git.mesalab.cn/fengweihao] mentioned this issue in [a commit|https://git.mesalab.cn/tsg/tsg-os-buildimage/-/commit/d9e0d744cf793e6afc9fc7298f736b23bd5ab818] of [TSG / tsg-os-buildimage|https://git.mesalab.cn/tsg/tsg-os-buildimage] on branch [update-certsorte-to-v3.0.1|https://git.mesalab.cn/tsg/tsg-os-buildimage/-/tree/update-certsorte-to-v3.0.1]:{quote}更新certstore到v3.0.1, 版本修改: OMPUB-897 修复本地缓存获取非可信证书key值错误问题{quote}
---
**gitlab** commented on *2023-04-13T16:53:13.079+0800*:
[冯伟浩|https://git.mesalab.cn/fengweihao] mentioned this issue in [a merge request|https://git.mesalab.cn/tsg/tsg-os-buildimage/-/merge_requests/1226] of [TSG / tsg-os-buildimage|https://git.mesalab.cn/tsg/tsg-os-buildimage] on branch [update-certsorte-to-v3.0.1|https://git.mesalab.cn/tsg/tsg-os-buildimage/-/tree/update-certsorte-to-v3.0.1]:{quote}更新certstore到v3.0.1, 版本修改: OMPUB-897 修复本地缓存获取非可信证书key值错误问题{quote}
---
**fengweihao** commented on *2023-04-13T17:03:34.796+0800*:
用如下方法规避此问题:
停止本地Redis服务
systemctl stop cert-redis.service
重启certstore服务
systemctl restart certstore
---
**gitlab** commented on *2023-04-13T19:54:34.582+0800*:
[冯伟浩|https://git.mesalab.cn/fengweihao] mentioned this issue in [a commit|https://git.mesalab.cn/tsg/tsg-os-buildimage/-/commit/cfef8e3275856f05590893ddfeae23fddec7a8c9] of [TSG / tsg-os-buildimage|https://git.mesalab.cn/tsg/tsg-os-buildimage] on branch [update-certsorte-to-v3.0.1|https://git.mesalab.cn/tsg/tsg-os-buildimage/-/tree/update-certsorte-to-v3.0.1]:{quote}更新certstore到v3.0.1, 版本修改: OMPUB-897 修复本地缓存获取非可信证书key值错误问题{quote}
---
2025-09-14 22:26:17 +00:00
# Attachments
2025-09-14 21:52:36 +00:00
2025-09-14 22:26:17 +00:00
Attachment: 屏幕截图(10).png
2025-09-14 22:27:11 +00:00
2025-09-14 22:26:17 +00:00
![屏幕截图(10).png](https://gfwleak.exec.li/admin/geedge-jira/raw/branch/master/attachment/37185/屏幕截图(10).png)
2025-09-14 21:52:36 +00:00
2025-09-14 22:26:17 +00:00
Attachment: 屏幕截图(11).png
2025-09-14 22:27:11 +00:00
2025-09-14 22:26:17 +00:00
![屏幕截图(11).png](https://gfwleak.exec.li/admin/geedge-jira/raw/branch/master/attachment/37184/屏幕截图(11).png)
2025-09-14 21:52:36 +00:00
2025-09-14 22:26:17 +00:00
Attachment: 屏幕截图(12).png
2025-09-14 22:27:11 +00:00
2025-09-14 22:26:17 +00:00
![屏幕截图(12).png](https://gfwleak.exec.li/admin/geedge-jira/raw/branch/master/attachment/37183/屏幕截图(12).png)
2025-09-14 21:52:36 +00:00
2025-09-14 22:26:17 +00:00
Attachment: 屏幕截图(13).png
2025-09-14 22:27:11 +00:00
2025-09-14 22:26:17 +00:00
![屏幕截图(13).png](https://gfwleak.exec.li/admin/geedge-jira/raw/branch/master/attachment/37182/屏幕截图(13).png)
2025-09-14 21:52:36 +00:00
2025-09-14 22:26:17 +00:00
Attachment: 屏幕截图(14).png
2025-09-14 22:27:11 +00:00
2025-09-14 22:26:17 +00:00
![屏幕截图(14).png](https://gfwleak.exec.li/admin/geedge-jira/raw/branch/master/attachment/37181/屏幕截图(14).png)
2025-09-14 21:52:36 +00:00
2025-09-14 22:26:17 +00:00
Attachment: 屏幕截图(15).png
2025-09-14 22:27:11 +00:00
2025-09-14 22:26:17 +00:00
![屏幕截图(15).png](https://gfwleak.exec.li/admin/geedge-jira/raw/branch/master/attachment/37180/屏幕截图(15).png)
2025-09-14 21:52:36 +00:00
2025-09-14 22:26:17 +00:00
Attachment: 屏幕截图(4).png
2025-09-14 22:27:11 +00:00
2025-09-14 22:26:17 +00:00
![屏幕截图(4).png](https://gfwleak.exec.li/admin/geedge-jira/raw/branch/master/attachment/37191/屏幕截图(4).png)
2025-09-14 21:52:36 +00:00
2025-09-14 22:26:17 +00:00
Attachment: 屏幕截图(5).png
2025-09-14 22:27:11 +00:00
2025-09-14 22:26:17 +00:00
![屏幕截图(5).png](https://gfwleak.exec.li/admin/geedge-jira/raw/branch/master/attachment/37190/屏幕截图(5).png)
Attachment: 屏幕截图(6).png
2025-09-14 22:27:11 +00:00
2025-09-14 22:26:17 +00:00
![屏幕截图(6).png](https://gfwleak.exec.li/admin/geedge-jira/raw/branch/master/attachment/37189/屏幕截图(6).png)
Attachment: 屏幕截图(7).png
2025-09-14 22:27:11 +00:00
2025-09-14 22:26:17 +00:00
![屏幕截图(7).png](https://gfwleak.exec.li/admin/geedge-jira/raw/branch/master/attachment/37188/屏幕截图(7).png)
Attachment: 屏幕截图(8).png
2025-09-14 22:27:11 +00:00
2025-09-14 22:26:17 +00:00
![屏幕截图(8).png](https://gfwleak.exec.li/admin/geedge-jira/raw/branch/master/attachment/37187/屏幕截图(8).png)
Attachment: 屏幕截图(9).png
2025-09-14 22:27:11 +00:00
2025-09-14 22:26:17 +00:00
![屏幕截图(9).png](https://gfwleak.exec.li/admin/geedge-jira/raw/branch/master/attachment/37186/屏幕截图(9).png)
2025-09-14 21:52:36 +00:00