Remove unnecessary lax Conscrypt hooks

This is covered more effectively by our injection of our system
certificate into the default trust store for all Conscrypt
implementations via the index.
This commit is contained in:
Tim Perry
2023-10-18 19:13:15 +02:00
parent e91199642d
commit 66873783ec
2 changed files with 31 additions and 40 deletions
-26
View File
@@ -66,23 +66,6 @@ const PINNING_FIXES = {
}
],
// --- Native Conscrypt OpenSSLSocketImpl
'com.android.org.conscrypt.OpenSSLSocketImpl': [
{
methodName: 'verifyCertificateChain',
replacement: () => NO_OP
}
],
'com.android.org.conscrypt.OpenSSLEngineSocketImpl': [
{
methodName: 'verifyCertificateChain',
overload: ['[Ljava.lang.Long;', 'java.lang.String'],
replacement: () => NO_OP
}
],
// --- Native Conscrypt CertPinManager
'com.android.org.conscrypt.CertPinManager': [
@@ -233,15 +216,6 @@ const PINNING_FIXES = {
}
],
// --- Apache Harmony version of OpenSSLSocketImpl (v similar to Conscrypt above)
'org.apache.harmony.xnet.provider.jsse.OpenSSLSocketImpl': [
{
methodName: 'verifyCertificateChain',
replacement: () => NO_OP
}
],
// --- PhoneGap sslCertificateChecker (https://github.com/EddyVerbruggen/SSLCertificateChecker-PhoneGap-Plugin)
'nl.xservices.plugins.sslCertificateChecker': [
+31 -14
View File
@@ -27,22 +27,39 @@ Java.perform(() => {
// by prepopulating all instances, we ensure that all TrustManagerImpls (and potentially other
// things) automatically trust our certificate specifically (without disabling validation entirely).
// This should apply to Android v7+ - previous versions used SSLContext & X509TrustManager.
const TrustedCertificateIndex = Java.use('com.android.org.conscrypt.TrustedCertificateIndex');
TrustedCertificateIndex.$init.overloads.forEach((overload) => {
overload.implementation = function () {
this.$init(...arguments);
// Index our cert as already trusted, right from the start:
this.index(cert);
[
'com.android.org.conscrypt.TrustedCertificateIndex',
'org.conscrypt.TrustedCertificateIndex', // Might be used (com.android is synthetic) - unclear
'org.apache.harmony.xnet.provider.jsse.TrustedCertificateIndex' // Used in Apache Harmony version of Conscrypt
].forEach((TrustedCertificateIndexClassname, i) => {
let TrustedCertificateIndex;
try {
TrustedCertificateIndex = Java.use(TrustedCertificateIndexClassname);
} catch (e) {
if (i === 0) {
throw new Error(`${TrustedCertificateIndexClassname} not found - could not inject system certificate`);
} else {
// Other classnames are optional fallbacks
return;
}
}
});
TrustedCertificateIndex.reset.overloads.forEach((overload) => {
overload.implementation = function () {
const result = this.reset(...arguments);
// Index our cert in here again, since the reset removes it:
this.index(cert);
return result;
};
TrustedCertificateIndex.$init.overloads.forEach((overload) => {
overload.implementation = function () {
this.$init(...arguments);
// Index our cert as already trusted, right from the start:
this.index(cert);
}
});
TrustedCertificateIndex.reset.overloads.forEach((overload) => {
overload.implementation = function () {
const result = this.reset(...arguments);
// Index our cert in here again, since the reset removes it:
this.index(cert);
return result;
};
});
});
// This effectively adds us to the system certs, and also defeats quite a bit of basic certificate