⚠️ This issue respects the following points: ⚠️
Bug description
The full deep detail of the bug can be found here :
The basics of the case , now X509 Certificate Authorities are issuing cross-signed certificates as per RFC 5280 . When you create a ECC-P256 or ECC-P384 signing request and send it to your chosen Certificate Authority you could end up with ECC certificate which is cross-signed with a normal SHA256 signature
rather than the normal standard ECSDA-SHA256 signature.
Basically a cross-signed RFC5280 certificate brakes the nginx webserver inside nextcloud if the version of nginx has not been compiled with Openssl 3.0.0 or later .
I used this version (shown below ) of nextcloud as a docker instance and it got broken by the above type of cross-signed certificate
https://hub.docker.com/r/linuxserver/nextcloud/
image: lscr.io/linuxserver/nextcloud
This docker instance uses nextcloud version 24.0.5.1
This above docker instance uses nginx version 1.20.2. is from 2022 which according to nginx support is end of life and should not be deployed and is compiled with openssl 1.1.1n which does not support cross-signed
ECC certificates.
The fixed required ,
- update the docker instance if it is in the control of the nextcloud team to the latest version of nginx and openssl
- update the system requirement of nextcloud so that states the new correct minimum version of nginx and openssl to be used so as to avoid this issue.
Steps to reproduce
Expected behavior
Nextcloud docker installations support ECC cross-signed RFC5280 certificates
Nextcloud Server version
32
Operating system
Other
PHP engine version
None
Web server
Nginx
Database engine version
None
Is this bug present after an update or on a fresh install?
None
Are you using the Nextcloud Server Encryption module?
None
What user-backends are you using?
Configuration report
List of activated Apps
Nextcloud Signing status
Nextcloud Logs
Additional info
No response
Bug description
The full deep detail of the bug can be found here :
The basics of the case , now X509 Certificate Authorities are issuing cross-signed certificates as per RFC 5280 . When you create a ECC-P256 or ECC-P384 signing request and send it to your chosen Certificate Authority you could end up with ECC certificate which is cross-signed with a normal SHA256 signature
rather than the normal standard ECSDA-SHA256 signature.
Basically a cross-signed RFC5280 certificate brakes the nginx webserver inside nextcloud if the version of nginx has not been compiled with Openssl 3.0.0 or later .
I used this version (shown below ) of nextcloud as a docker instance and it got broken by the above type of cross-signed certificate
https://hub.docker.com/r/linuxserver/nextcloud/
image: lscr.io/linuxserver/nextcloud
This docker instance uses nextcloud version 24.0.5.1
This above docker instance uses nginx version 1.20.2. is from 2022 which according to nginx support is end of life and should not be deployed and is compiled with openssl 1.1.1n which does not support cross-signed
ECC certificates.
The fixed required ,
Steps to reproduce
Expected behavior
Nextcloud docker installations support ECC cross-signed RFC5280 certificates
Nextcloud Server version
32
Operating system
Other
PHP engine version
None
Web server
Nginx
Database engine version
None
Is this bug present after an update or on a fresh install?
None
Are you using the Nextcloud Server Encryption module?
None
What user-backends are you using?
Configuration report
List of activated Apps
Nextcloud Signing status
Nextcloud Logs
Additional info
No response