Skip to content

Fix: Prevent node-forge crash due to unsupported certificate subject attributes#27

Open
NikosRig wants to merge 1 commit into
sannysoft:masterfrom
NikosRig:fix/unsupported-cert-subject-attributes
Open

Fix: Prevent node-forge crash due to unsupported certificate subject attributes#27
NikosRig wants to merge 1 commit into
sannysoft:masterfrom
NikosRig:fix/unsupported-cert-subject-attributes

Conversation

@NikosRig

Copy link
Copy Markdown

What this PR does
This PR adds a safeguard when creating fake certificates using the CA. Some real-world certificates include non-standard subject fields (like jurisdictionC, businessCategory, etc.) that node-forge doesn’t recognize. When setSubject() encounters these, it throws an error:

typescript
Copy
Edit
Error: Attribute type not specified.
This PR filters out any unsupported subject fields from the original certificate before passing them to forge, ensuring stable fake certificate generation.

Why it matters
This fixes runtime crashes when intercepting HTTPS requests with such certificates, improving reliability and compatibility of the proxy.

How it's done
Introduces a whitelist of supported name and shortName attributes.

Only those supported by node-forge are passed to cert.setSubject().

✅ Verified that it gracefully skips unknown fields and successfully creates a valid certificate.

…fields

Filters out unknown subject attributes (e.g., jurisdictionC) when generating fake certs with node-forge. This avoids the "Attribute type not specified" error caused by fields not recognized by node-forge.
@NikosRig NikosRig closed this Mar 29, 2025
@NikosRig NikosRig reopened this Mar 29, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant