mirror of
https://github.com/wiremock/WireMock.Net.git
synced 2026-07-26 14:58:39 +02:00
Support for PEM certificates when using ssl #434
Closed
opened 2025-12-29 15:23:42 +01:00 by adam
·
13 comments
No Branch/Tag Specified
master
1341-mapping-json
stef-aspire-tests-updates
bug/973-TinyMapper
bug/1149-AppendGuidToSavedMappingFile
feature/1150-DockerImageVersion
61
stef-1108
stef-1097
stef-1083-MessageOptions_Type_Conflict
stef-1062-logger
stef-IgnoreOpenApiErrors
stef-928-TypeLoadException-FluentAssertions-net472
nunit
stef-849
stef-847-regex-questionmark
http_verb
WireMockServerContext
webapp
ai
CommandLineArgumentsParser
2.13.0
2.12.0
2.11.0
2.10.0
2.9.0
2.8.0
2.7.0
2.6.0
2.5.0
2.4.0
2.3.0
2.2.0
2.1.0
2.0.0
1.25.0
1.24.0
1.23.0
1.22.0
1.21.0
1.20.0
1.19.0
1.18.0
1.17.0
1.16.0
1.15.0
1.14.0
1.13.0
1.12.0
1.11.2
1.11.0
1.10.1
1.10.0
1.9.1
1.9.0
1.8.18
1.8.17
1.8.16
1.8.15
1.8.14
1.8.13
1.8.12
1.8.11
1.8.10
1.8.9
1.8.8
1.8.7
1.8.6
1.8.5
1.8.3
1.8.2
1.8.1
1.8.0
1.7.4
1.7.3
1.7.2
1.7.1
1.7.0
1.6.12
1.6.11
1.6.10
1.6.9
1.6.8
1.6.7
1.6.6
1.6.5
1.6.4
1.6.3
1.6.2
1.6.1
1.6.0
1.5.62
1.5.61
1.5.60
1.5.59
1.5.58
1.5.57
1.5.56
1.5.55
1.5.54
1.5.53
1.5.52
1.5.51
1.5.50
1.5.49
1.5.48
1.5.47
1.5.46
1.5.45
1.5.44
1.5.43
1.5.42
1.5.41
1.5.40
1.5.39
1.5.38
1.5.37
1.5.36
1.5.35
1.5.34
1.5.33
1.5.32
1.5.31
1.5.30
1.5.29
1.5.28
1.5.27
1.5.26
1.5.25
1.5.24
1.5.23
1.5.22
1.5.21
1.5.20
1.5.19
1.5.18
1.5.17
1.5.16
1.5.15
1.5.14
1.5.13
1.5.12
1.5.11
1.5.10
1.5.9
1.5.8
1.5.7
1.5.6
1.5.5
1.5.4
1.5.3
1.5.2
1.5.1
1.5.0
1.4.43
1.4.42
1.4.41
1.4.40
1.4.39
1.4.38
1.4.37
1.4.36
1.4.35
1.4.34
1.4.33
1.4.32
1.4.31
1.4.30
1.4.29
1.4.28
1.4.27
1.4.26
1.4.25
1.4.24
1.4.23
1.4.22
1.4.21
1.4.20
1.4.19
1.4.18
1.4.17
1.4.16
1.4.15
1.4.14
1.4.13
1.4.12
1.4.11
1.4.10
1.4.9
1.4.8
1.4.7
1.4.6
1.4.5
1.4.4
1.4.3
1.4.2
1.4.1
1.4.0
1.3.10
1.3.9
1.3.8
1.3.6
1.3.5
1.3.4
1.3.3
1.3.2
1.3.1
1.3.0
1.2.18
1.2.17
1.2.16
1.2.15
1.2.14
1.2.13
1.2.12
1.2.11.0
1.2.10
1.2.9.0
1.2.8.0
1.2.7.0
1.2.6.0
1.2.5.0
1.2.4.0
1.2.3.0
1.2.2.0
1.2.1.0
1.2.0.0
1.1.10
1.1.9.0
1.1.8.0
1.1.7.0
1.1.6.0
1.1.5.0
1.1.3.0
1.1.2.0
1.1.1.0
1.1.0.0
1.0.43.0
1.0.42.0
1.0.41.0
1.0.40.0
1.0.39.0
1.0.38.0
1.0.37.0
1.0.36.0
1.0.35.0
1.0.34.0
1.0.33.0
1.0.32.0
1.0.31.0
1.0.29.0
1.0.28.0
1.0.25.0
1.0.24.0
1.0.23.0
1.0.22.0
1.0.21.0
1.0.20.0
1.0.19.0
1.0.18.0
1.0.17.0
1.0.16.0
1.0.15.0
1.0.14.0
1.0.13.0
1.0.12.0
1.0.11.0
1.0.10.0
1.0.9.0
1.0.8.0
1.0.7.0
1.0.6.1
1.0.6
1.0.5
1.0.4.21
1.0.4.20
1.0.4.19
1.0.4.18
1.0.4.17
1.0.4.16
1.0.4.15
1.0.4.14
1.0.4.13
1.0.4.12
1.0.4.11
1.0.4.10
1.0.4.9
1.0.4.8
1.0.4.7
1.0.4.6
1.0.4.5
1.0.4.4
1.0.4.3
1.0.4.2
1.0.4.1
1.0.4.0
1.0.3.20
1.0.3.19
1.0.3.18
1.0.3.17
1.0.3.16
1.0.3.15
1.0.3.14
1.0.3.13
1.0.3.12
1.0.3.11
1.0.3.10
1.0.3.9
1.0.3.8
1.0.3.7
1.0.3.6
1.0.3.5
1.0.3.4
1.0.3.3
1.0.3.2
1.0.3.1
1.0.3.0
1.0.2.13
1.0.2.12
1.0.2.11
1.0.2.10
1.0.2.9
1.0.2.8
1.0.2.7
1.0.2.6
1.0.2.5
1.0.2.4
1.0.2.1
1.0.2.0
1.0.1.5
1.0.1.3
1.0.1.2
1.0.1.1
1.0.0.0
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Assignees
adam (Adam Melkus)
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/WireMock.Net-wiremock#434
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @kriebb on GitHub (Aug 11, 2022).
Originally assigned to: @StefH on GitHub.
Is your feature request related to a problem? Please describe.
When running dotnet test on a builderserver using systemtests with Wiremock ssl custom certificates, a pfx can be specified, but gives problems when loading the pfx on a build server:
I can replay this on a buildserver creating a test just running this code
However when using the PEM format, this works.
Describe the solution you'd like
In the CertificateLoader you have the code
You can modify the if statements to look at the extension.
If(filepath.Endswith(pem)return
X509.LoadFromPem(filepath,password)where the password is the filepath to the keyOther solution can be to use a
IX509Certificate2Factorythat you can supply using the services or to the add it to the settings and when that is available, use the factory... any suggestions?
Describe alternatives you've considered
Try to persude the devops people to give access to the certification store
google, and try to convert the pfx to other supported pfx`s formats like DER.
Is your feature request supported by WireMock (java version)? Please provide details.
PEM doesnt seem to be supported. Only jwks on wiremock.org
Additional context
@StefH commented on GitHub (Aug 11, 2022):
The easiest is to use
If(filepath.Endswith(pem).Please note that this is only supported for netcoreapp3.1 ; .NET 5.0 and higher.
You can try preview version
1.5.3-ci-16350
@kriebb commented on GitHub (Aug 11, 2022):
Thx for your fast response!
tried it, but somehow got this message:
Use it like this:
this is also more helpfull
Seems like something is not working with Kestrel en Pem x509Certificate2.
According to this post: https://stackoverflow.com/questions/67147703/get-the-server-mode-ssl-must-use-a-certificate-with-the-associated-private-key
The pfx needs to be created inmemory from the pem file and exported with a random key then.
Something to tryout tough. sigh
Don't know if you want o include something like this, so I can try it out? (copy paste from the stackoverflow tough.
If however, you'd rather have me test it in a personal project to mimic it, let me know.
@StefH commented on GitHub (Aug 11, 2022):
Can you try
1.5.3-ci-16353
@kriebb commented on GitHub (Aug 11, 2022):
Yes,
Same result:
settings are used like this:
other stacktraces that be usefull
I did see you, you didnt do the "trick" with the line
certificate.Export(X509ContentType.Pfx, pass), passwich I can understand. I guess it will also try to have some rights again for accessing the cert store. But I didnt try it out yet.@StefH commented on GitHub (Aug 11, 2022):
Code updated with:
return new X509Certificate2(certificate.Export(X509ContentType.Pfx, pass), pass);
New preview will be available within few minutes.
@kriebb commented on GitHub (Aug 11, 2022):
blush what is the preview? cant seem to find it on actions ?
will try it tomorrow :)
@StefH commented on GitHub (Aug 11, 2022):
@kriebb
See this wiki:
https://github.com/WireMock-Net/WireMock.Net/wiki/MyGet-preview-versions
Also if you can send me test PEM = password (or tell me how to generate it), I can also test on my machine.
@StefH commented on GitHub (Aug 11, 2022):
Latest preview (1.5.3-ci-16357) should work fine.
I based my example + logic on https://www.scottbrady91.com/c-sharp/pem-loading-in-dotnet-core-and-dotnet
See https://github.com/WireMock-Net/WireMock.Net/pull/787/files#diff-721297a29d1cb2c8d0ca5463eea9738306dd5416115e04711d2c7bf20576d71b
@kriebb commented on GitHub (Aug 12, 2022):
Sorry, the same behavior occurs.
However, intresting read that you mention.
When I read at the end:
So you cant pass an x509Certificate to Kestrel, because it fucks something up in windows when opening an SSLStream ( as designed it seems)
The CI pipeline at the company dont give any access to the system keyset. So the current solution that is built in ( works fine on my machine tough)
However, when I read further more on:
So just passing filepaths to the KestrelEndPointOptions should be able to work.
Are you in for a final try? after then, I give up. But that article that you mentioned, really confirms what I was thinking, You dont need access to the store using PEM ( or am I misreading it?)
You asked on how I was creating the PEM
Using the following:
https://www.cryptool.org/en/cto/openssl
@StefH commented on GitHub (Aug 12, 2022):
1
BTW : Yesterday I did quickly test creating an RSA Certificate using that website, however I found that only a EC Certificate did work in my example app.
So can you also try that?
2
The Kestrel options you mention:
This is already supported by WireMock.Net, see https://github.com/WireMock-Net/WireMock.Net/wiki/KestrelServerOptions
@StefH commented on GitHub (Aug 12, 2022):
@kriebb RSA does also work when I follow https://www.scottbrady91.com/openssl/creating-rsa-keys-using-openssl
See my PR for details.
@kriebb commented on GitHub (Aug 16, 2022):
Seems to work 👍
What also a good way of having a valid certificate (if you work with local host is using the dotnet dev-certs https -v -ep $(HOME).aspnet\https --format pem"
@StefH commented on GitHub (Aug 16, 2022):
OK, I'll merge the code to master and close this issue.