Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

mTLS is buggy for a long time? #38410

Open
2 of 6 tasks
fetuffani opened this issue May 18, 2024 · 0 comments
Open
2 of 6 tasks

mTLS is buggy for a long time? #38410

fetuffani opened this issue May 18, 2024 · 0 comments

Comments

@fetuffani
Copy link

fetuffani commented May 18, 2024

Description

I have a couple of services that i self host and to avoid unauthorized access I've added to my cloudflare firewall a mTLS certificate check to ensure that no one reach certain endpoints of my services.

The CF firewall is correctly set but Brave often ignore my mTLS certificate and I'm not able to access my services.
After a few Brave restarts, it is able to pick the mTLS certificate and I can access the services but 80%ish of the time it fails

I can confirm that both CF firewall and the certificate is correctly set as other browsers have no issues using it, even Brave can use from time to time thought very intermittently

PS: I've been watching this behaviour for at least 3 months from now, since I've set up the mTLS handshake on my WAF

Steps to reproduce

  1. Install a mTLS certificate on client and set it up on the server (Cloudflare WAF in this case)
  2. Try to access the webpage

Actual result

The mTLS certificate is not recognized and the server results in 403 Forbidden

Expected result

Brave ask if I really want to use the specified mTLS certificate to access the webpage

Reproduces how often

Intermittent issue

Brave version (brave://version info)

Brave 1.66.110 (Revision de593d76e2ca4d02faa85bf1ca27bcf3ee46793c)
Chromium: 125.0.6422.60 (64bits)
Windows 10

Channel information

  • release (stable)
  • beta
  • nightly

Reproducibility

  • with Brave Shields disabled
  • with Brave Rewards disabled
  • in the latest version of Chrome

Miscellaneous information

  • Also buggy in private mode
  • Disabled every extension
@rebron rebron added this to Untriaged Backlog in Security & Privacy via automation May 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Security & Privacy
  
Untriaged Backlog
Development

No branches or pull requests

1 participant