Skip to content

[Bug]: Nextcloud internal components : nginx and openssl that need to be upgrade to support RFC5280 cross signed certifcates #64886

Description

@SIBA-DK

⚠️ This issue respects the following points: ⚠️

  • This is not a troubleshooting question, general support matter, or webserver/proxy problem, but likely a bug (if unsure, ask the Community Help Forum).
  • This issue is not already reported on Github OR solved at the Community Help Forum (I've searched!).
  • I'm using a maintained major version of Nextcloud Server and tested against the latest patch level. (Supported major versions and current patch levels).
  • I agree to follow Nextcloud's Code of Conduct.
  • I've tried my best to provide clear reproduction steps that someone unfamiliar with this bug could use to reproduce it.

Bug description

The full deep detail of the bug can be found here :

The basics of the case , now X509 Certificate Authorities are issuing cross-signed certificates as per RFC 5280 . When you create a ECC-P256 or ECC-P384 signing request and send it to your chosen Certificate Authority you could end up with ECC certificate which is cross-signed with a normal SHA256 signature
rather than the normal standard ECSDA-SHA256 signature.

Basically a cross-signed RFC5280 certificate brakes the nginx webserver inside nextcloud if the version of nginx has not been compiled with Openssl 3.0.0 or later .

I used this version (shown below ) of nextcloud as a docker instance and it got broken by the above type of cross-signed certificate

https://hub.docker.com/r/linuxserver/nextcloud/
image: lscr.io/linuxserver/nextcloud

This docker instance uses nextcloud version 24.0.5.1

This above docker instance uses nginx version 1.20.2. is from 2022 which according to nginx support is end of life and should not be deployed and is compiled with openssl 1.1.1n which does not support cross-signed
ECC certificates.

The fixed required ,

  • update the docker instance if it is in the control of the nextcloud team to the latest version of nginx and openssl
  • update the system requirement of nextcloud so that states the new correct minimum version of nginx and openssl to be used so as to avoid this issue.

Steps to reproduce

Expected behavior

Nextcloud docker installations support ECC cross-signed RFC5280 certificates

Nextcloud Server version

32

Operating system

Other

PHP engine version

None

Web server

Nginx

Database engine version

None

Is this bug present after an update or on a fresh install?

None

Are you using the Nextcloud Server Encryption module?

None

What user-backends are you using?

  • Default user-backend (database)
  • LDAP/ Active Directory
  • SSO - SAML
  • Other

Configuration report

List of activated Apps

Nextcloud Signing status

Nextcloud Logs

Additional info

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    0. Needs triagePending check for reproducibility or if it fits our roadmap32-feedbackbug

    Type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions