GNU bug report logs -
#25518
25.1.91; url-retrieve does not work with https over proxy
Previous Next
Reported by: Andreas Schwab <schwab <at> linux-m68k.org>
Date: Tue, 24 Jan 2017 13:26:01 UTC
Severity: normal
Found in version 25.1.91
Done: Lars Ingebrigtsen <larsi <at> gnus.org>
Bug is archived. No further changes may be made.
To add a comment to this bug, you must first unarchive it, by sending
a message to control AT debbugs.gnu.org, with unarchive 25518 in the body.
You can then email your comments to 25518 AT debbugs.gnu.org in the normal way.
Toggle the display of automated, internal messages from the tracker.
Report forwarded
to
bug-gnu-emacs <at> gnu.org
:
bug#25518
; Package
emacs
.
(Tue, 24 Jan 2017 13:26:01 GMT)
Full text and
rfc822 format available.
Acknowledgement sent
to
Andreas Schwab <schwab <at> linux-m68k.org>
:
New bug report received and forwarded. Copy sent to
bug-gnu-emacs <at> gnu.org
.
(Tue, 24 Jan 2017 13:26:01 GMT)
Full text and
rfc822 format available.
Message #5 received at submit <at> debbugs.gnu.org (full text, mbox):
url-retrieve should use CONNECT when talking to a https URL over a proxy
and then talk over the connection as if not using a proxy.
;; use locally running privoxy as proxy
(setq url-proxy-services '(("https" . "localhost:8118")))
(with-current-buffer (url-retrieve-synchronously "https://www.heise.de")
(buffer-string)) => "HTTP/1.1 200 Connection established\n\n"
Andreas.
--
Andreas Schwab, schwab <at> linux-m68k.org
GPG Key fingerprint = 58CA 54C7 6D53 942B 1756 01D3 44D5 214B 8276 4ED5
"And now for something completely different."
Information forwarded
to
bug-gnu-emacs <at> gnu.org
:
bug#25518
; Package
emacs
.
(Tue, 24 Jan 2017 20:34:02 GMT)
Full text and
rfc822 format available.
Message #8 received at 25518 <at> debbugs.gnu.org (full text, mbox):
Andreas Schwab writes:
> url-retrieve should use CONNECT when talking to a https URL over a proxy
> and then talk over the connection as if not using a proxy.
>
> ;; use locally running privoxy as proxy
> (setq url-proxy-services '(("https" . "localhost:8118")))
> (with-current-buffer (url-retrieve-synchronously "https://www.heise.de")
> (buffer-string)) => "HTTP/1.1 200 Connection established\n\n"
Is this identical to #11788? If so, this is fixed only on master because
it was deemed too risky for emacs-25. I'm still of the opinion that this
is a serious security issue, because of the possible silent fallback to
http without the user noticing. I'm always running my Emacs with
3c623c26a manually backported.
-David
Information forwarded
to
bug-gnu-emacs <at> gnu.org
:
bug#25518
; Package
emacs
.
(Tue, 24 Sep 2019 08:32:02 GMT)
Full text and
rfc822 format available.
Message #11 received at 25518 <at> debbugs.gnu.org (full text, mbox):
Andreas Schwab <schwab <at> linux-m68k.org> writes:
> url-retrieve should use CONNECT when talking to a https URL over a proxy
> and then talk over the connection as if not using a proxy.
>
> ;; use locally running privoxy as proxy
> (setq url-proxy-services '(("https" . "localhost:8118")))
> (with-current-buffer (url-retrieve-synchronously "https://www.heise.de")
> (buffer-string)) => "HTTP/1.1 200 Connection established\n\n"
I tried this with tinyproxy and Emacs 27, and it worked for me, so I'm
guessing this has been fixed in the meantime, and I'm closing the bug
report.
Please reopen if this is still an issue.
--
(domestic pets only, the antidote for overdose, milk.)
bloggy blog: http://lars.ingebrigtsen.no
bug closed, send any further explanations to
25518 <at> debbugs.gnu.org and Andreas Schwab <schwab <at> linux-m68k.org>
Request was from
Lars Ingebrigtsen <larsi <at> gnus.org>
to
control <at> debbugs.gnu.org
.
(Tue, 24 Sep 2019 08:33:02 GMT)
Full text and
rfc822 format available.
bug archived.
Request was from
Debbugs Internal Request <help-debbugs <at> gnu.org>
to
internal_control <at> debbugs.gnu.org
.
(Tue, 22 Oct 2019 11:24:05 GMT)
Full text and
rfc822 format available.
This bug report was last modified 5 years and 236 days ago.
Previous Next
GNU bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson.