Skip to content

crypto/tls: FIPS 140-3 certificate key check is skipped when InsecureSkipVerify=true [1.25 backport] #80076

Description

@gopherbot

@FiloSottile requested issue #80074 to be considered for backport to the next 1.25 minor release.

Yeah this is a bug, thank you for the report.

@gopherbot please open backport issues, this can hide a non-compliant connection. (It will not cause a compliant connection to become non-compliant, but it will let a non-compliant connection happen instead of erroring out, while currently crypto/tls does strict enforcement even in fips140=on mode.)

Metadata

Metadata

Assignees

No one assigned

    Labels

    CherryPickCandidateUsed during the release process for point releases

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions