Skip to content

ssl: Add :SSLContext config option to use OpenSSL::SSL::SSLContext as-is - #62

Merged
kou merged 1 commit into
ruby:masterfrom
kou:ssl-context
Oct 1, 2026
Merged

kou merged 1 commit into
ruby:masterfrom
kou:ssl-context

Conversation

@kou

@kou kou commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

#52

The :SSL* config options cover only a part of
OpenSSL::SSL::SSLContext features such as #add_certificate and #groups=. Adding a config option for each feature isn't scalable.

If :SSLContext is specified, the other :SSL* config options are ignored.

This also adds DRb::DRbSSLSocket::BasicSSLConfig, which can be passed to DRb::DRbSSLSocket.open and .open_server like DRb::DRbSSLSocket::SSLConfig.

junaruga added a commit to junaruga/ruby-pqc-test that referenced this pull request Sep 30, 2026
Update development job scripts to use the :SSLContext config option
from ruby/drb PR #62 instead of the custom :SSL* options from the
wip/support-pqc branch. Each original config option is translated to
the equivalent OpenSSL::SSL::SSLContext attribute:

* SSLCertificates/SSLCertificate/SSLPrivateKey -> ctx.add_certificate
* SSLGroups -> ctx.groups
* SSLSignatureAlgorithms -> ctx.sigalgs
* SSLVerifyMode -> ctx.verify_mode
* SSLCACertificateFile -> ctx.ca_file
* SSLCertificateStore -> ctx.cert_store
* SSLClientCA -> ctx.client_ca

Auto-generated cert scripts now generate keys and self-signed
certificates directly using OpenSSL::PKey.generate_key and
OpenSSL::X509::Certificate.

Also update the clone URL in all development jobs from
junaruga/ruby-drb wip/support-pqc to kou/drb ssl-context.

Assisted-by: Claude:Opus 4.6
junaruga added a commit to junaruga/ruby-pqc-test that referenced this pull request Sep 30, 2026
Update development job scripts to use the :SSLContext config option
from ruby/drb PR #62 instead of the custom :SSL* options from the
wip/support-pqc branch. Each original config option is translated to
the equivalent OpenSSL::SSL::SSLContext attribute:

* SSLCertificates/SSLCertificate/SSLPrivateKey -> ctx.add_certificate
* SSLGroups -> ctx.groups
* SSLSignatureAlgorithms -> ctx.sigalgs
* SSLVerifyMode -> ctx.verify_mode
* SSLCACertificateFile -> ctx.ca_file
* SSLCertificateStore -> ctx.cert_store
* SSLClientCA -> ctx.client_ca

Auto-generated cert scripts now generate keys and self-signed
certificates directly using OpenSSL::PKey.generate_key and
OpenSSL::X509::Certificate.

Also update the clone URL in all development jobs from
junaruga/ruby-drb wip/support-pqc to kou/drb ssl-context.

Assisted-by: Claude:Opus 4.6
junaruga added a commit to junaruga/ruby-pqc-test that referenced this pull request Sep 30, 2026
Update development job scripts to use the :SSLContext config option
from ruby/drb PR #62 instead of the custom :SSL* options from the
wip/support-pqc branch. Each original config option is translated to
the equivalent OpenSSL::SSL::SSLContext attribute:

* SSLCertificates/SSLCertificate/SSLPrivateKey -> ctx.add_certificate
* SSLGroups -> ctx.groups
* SSLSignatureAlgorithms -> ctx.sigalgs
* SSLVerifyMode -> ctx.verify_mode
* SSLCACertificateFile -> ctx.ca_file
* SSLCertificateStore -> ctx.cert_store
* SSLClientCA -> ctx.client_ca

Auto-generated cert scripts now generate keys and self-signed
certificates directly using OpenSSL::PKey.generate_key and
OpenSSL::X509::Certificate.

Also update the clone URL in all development jobs from
junaruga/ruby-drb wip/support-pqc to kou/drb ssl-context.

Assisted-by: Claude:Opus 4.6

@junaruga junaruga left a comment •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this PR.

First, this PR is fantastic change to make drb scalable not depending on the changes of OpenSSL::SSL::SSLContext. We have an option to use DRb::DRbSSLSocket::BasicSSLConfig in PQC use cases. We also have an option to deprecate the DRb::DRbSSLSocket::SSLConfig not scaling if the used RSA is really outdated in the future.

I tested the PQC use cases worked with ML-KEM, ML-DSA single server, and ML-DSA/RSA multiple server cases via PR junaruga/ruby-pqc-test#52 on my Ruby PQC proof-of-concept repository.

I want to request one small thing to describe the term ":SSLContext config option" consistently and explicitly in the code comments, instead of just ":SSLContext", because I stumbled to understand what the ":SSLContext" is.

Other than that, the PR looks okay.

I don't want you to close the issue ticket #52 yet even after the PR is merged, if you like. Because I intended the issue ticket #52 was the top level ticket to manage PRs to support PQC. That's why the ticket has PQC related pull-requests section, and the Ruby PQC ticket https://bugs.ruby-lang.org/issues/22068 refers to the top level ticket #52 by "ruby/drb: bundled gem - issue link - Add PQC features". I think there is one remaining task for us to say that drb supports PQC. That is to document drb's PQC supported policy and guide for users. But if you are not comfortable not to close the issue ticket, that's okay for me.

Comment thread lib/drb/ssl.rb Outdated
# You can also specify an OpenSSL::SSL::SSLContext by :SSLContext.
# If :SSLContext is specified, it's used as-is and the other :SSL*
# options are ignored. This is useful to use features that aren't
# covered by the :SSL* options:

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The term :SSLContext is used in some parts of the code comment of lib/drb/ssl.rb. I would prefer that the ":SSLContext" is described as ":SSLContext config option" or ":SSLContext option" explicitly insted of just ":SSLContext" in the code comments of lib/drb/ssl.rb, because I was a bit stumbled about what :SSLContext is.

…` as-is

rubyGH-52

The `:SSL*` config options cover only a part of
`OpenSSL::SSL::SSLContext` features such as `#add_certificate` and
`#groups=`. Adding a config option for each feature isn't scalable.

If `:SSLContext` is specified, the other `:SSL*` config options are
ignored.

This also adds `DRb::DRbSSLSocket::BasicSSLConfig`, which can be passed
to `DRb::DRbSSLSocket.open` and `.open_server` like
`DRb::DRbSSLSocket::SSLConfig`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kou

kou commented Oct 1, 2026

Copy link
Copy Markdown
Member Author

OK. I've updated the comments: https://github.com/ruby/drb/compare/021d0941d39fa5944c5e677a0884973d5a5f468f..3a4c7f4c1fac9f1da13fabdeafdaa68965c2b1ac

I'll merge this without "Fix #52". You can open a separated PR that adds some documents after we merge this.

@kou
kou merged commit e213357 into ruby:master Oct 1, 2026
28 checks passed
@kou
kou deleted the ssl-context branch October 1, 2026 01:50

@junaruga junaruga left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All right. Your change for code comments looks good to me. Thanks.

This branch was successfully deployed

1 active deployment
release — 3a4c7f4c Deployed Oct 1, 2026 by kou via RubyGems #61
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants