Skip to content
This repository was archived by the owner on Apr 22, 2023. It is now read-only.
This repository was archived by the owner on Apr 22, 2023. It is now read-only.

TLS Client 'rejectUnauthorized' must default to true #3949

@hueniverse

Description

@hueniverse

No idea why server cert validation is off by default. This is a major security issue since the vast majority of developers are not aware of this and will leave it as-is. If you fail to check the server's certificate, you have zero protection against a long list of attacks.

Yes - changing the default is likely to break stuff. THAT'S A GOOD THING!

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions