ssl: Add :SSLContext config option to use OpenSSL::SSL::SSLContext as-is - #62
Conversation
Update development job scripts to use the :SSLContext config option from ruby/drb PR #62 instead of the custom :SSL* options from the wip/support-pqc branch. Each original config option is translated to the equivalent OpenSSL::SSL::SSLContext attribute: * SSLCertificates/SSLCertificate/SSLPrivateKey -> ctx.add_certificate * SSLGroups -> ctx.groups * SSLSignatureAlgorithms -> ctx.sigalgs * SSLVerifyMode -> ctx.verify_mode * SSLCACertificateFile -> ctx.ca_file * SSLCertificateStore -> ctx.cert_store * SSLClientCA -> ctx.client_ca Auto-generated cert scripts now generate keys and self-signed certificates directly using OpenSSL::PKey.generate_key and OpenSSL::X509::Certificate. Also update the clone URL in all development jobs from junaruga/ruby-drb wip/support-pqc to kou/drb ssl-context. Assisted-by: Claude:Opus 4.6
Update development job scripts to use the :SSLContext config option from ruby/drb PR #62 instead of the custom :SSL* options from the wip/support-pqc branch. Each original config option is translated to the equivalent OpenSSL::SSL::SSLContext attribute: * SSLCertificates/SSLCertificate/SSLPrivateKey -> ctx.add_certificate * SSLGroups -> ctx.groups * SSLSignatureAlgorithms -> ctx.sigalgs * SSLVerifyMode -> ctx.verify_mode * SSLCACertificateFile -> ctx.ca_file * SSLCertificateStore -> ctx.cert_store * SSLClientCA -> ctx.client_ca Auto-generated cert scripts now generate keys and self-signed certificates directly using OpenSSL::PKey.generate_key and OpenSSL::X509::Certificate. Also update the clone URL in all development jobs from junaruga/ruby-drb wip/support-pqc to kou/drb ssl-context. Assisted-by: Claude:Opus 4.6
Update development job scripts to use the :SSLContext config option from ruby/drb PR #62 instead of the custom :SSL* options from the wip/support-pqc branch. Each original config option is translated to the equivalent OpenSSL::SSL::SSLContext attribute: * SSLCertificates/SSLCertificate/SSLPrivateKey -> ctx.add_certificate * SSLGroups -> ctx.groups * SSLSignatureAlgorithms -> ctx.sigalgs * SSLVerifyMode -> ctx.verify_mode * SSLCACertificateFile -> ctx.ca_file * SSLCertificateStore -> ctx.cert_store * SSLClientCA -> ctx.client_ca Auto-generated cert scripts now generate keys and self-signed certificates directly using OpenSSL::PKey.generate_key and OpenSSL::X509::Certificate. Also update the clone URL in all development jobs from junaruga/ruby-drb wip/support-pqc to kou/drb ssl-context. Assisted-by: Claude:Opus 4.6
There was a problem hiding this comment.
I reviewed this PR.
First, this PR is fantastic change to make drb scalable not depending on the changes of OpenSSL::SSL::SSLContext. We have an option to use DRb::DRbSSLSocket::BasicSSLConfig in PQC use cases. We also have an option to deprecate the DRb::DRbSSLSocket::SSLConfig not scaling if the used RSA is really outdated in the future.
I tested the PQC use cases worked with ML-KEM, ML-DSA single server, and ML-DSA/RSA multiple server cases via PR junaruga/ruby-pqc-test#52 on my Ruby PQC proof-of-concept repository.
I want to request one small thing to describe the term ":SSLContext config option" consistently and explicitly in the code comments, instead of just ":SSLContext", because I stumbled to understand what the ":SSLContext" is.
Other than that, the PR looks okay.
I don't want you to close the issue ticket #52 yet even after the PR is merged, if you like. Because I intended the issue ticket #52 was the top level ticket to manage PRs to support PQC. That's why the ticket has PQC related pull-requests section, and the Ruby PQC ticket https://bugs.ruby-lang.org/issues/22068 refers to the top level ticket #52 by "ruby/drb: bundled gem - issue link - Add PQC features". I think there is one remaining task for us to say that drb supports PQC. That is to document drb's PQC supported policy and guide for users. But if you are not comfortable not to close the issue ticket, that's okay for me.
| # You can also specify an OpenSSL::SSL::SSLContext by :SSLContext. | ||
| # If :SSLContext is specified, it's used as-is and the other :SSL* | ||
| # options are ignored. This is useful to use features that aren't | ||
| # covered by the :SSL* options: |
There was a problem hiding this comment.
The term :SSLContext is used in some parts of the code comment of lib/drb/ssl.rb. I would prefer that the ":SSLContext" is described as ":SSLContext config option" or ":SSLContext option" explicitly insted of just ":SSLContext" in the code comments of lib/drb/ssl.rb, because I was a bit stumbled about what :SSLContext is.
…` as-is rubyGH-52 The `:SSL*` config options cover only a part of `OpenSSL::SSL::SSLContext` features such as `#add_certificate` and `#groups=`. Adding a config option for each feature isn't scalable. If `:SSLContext` is specified, the other `:SSL*` config options are ignored. This also adds `DRb::DRbSSLSocket::BasicSSLConfig`, which can be passed to `DRb::DRbSSLSocket.open` and `.open_server` like `DRb::DRbSSLSocket::SSLConfig`. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
OK. I've updated the comments: https://github.com/ruby/drb/compare/021d0941d39fa5944c5e677a0884973d5a5f468f..3a4c7f4c1fac9f1da13fabdeafdaa68965c2b1ac I'll merge this without "Fix #52". You can open a separated PR that adds some documents after we merge this. |
junaruga
left a comment
There was a problem hiding this comment.
All right. Your change for code comments looks good to me. Thanks.
#52
The
:SSL*config options cover only a part ofOpenSSL::SSL::SSLContextfeatures such as#add_certificateand#groups=. Adding a config option for each feature isn't scalable.If
:SSLContextis specified, the other:SSL*config options are ignored.This also adds
DRb::DRbSSLSocket::BasicSSLConfig, which can be passed toDRb::DRbSSLSocket.openand.open_serverlikeDRb::DRbSSLSocket::SSLConfig.