T09 · Insecure Skill Coding Practices
- Location
references/sdk-installation-guide.md:122- Finding
TLS Certificate Verification Disabled in SDK Troubleshooting Guidance
- Content
View full analysis
Vulnerability Details
File Location:
references/sdk-installation-guide.md, lines 122–134
Vulnerability Type: Improper certificate validation
Risk Level: Mediumpython # Disable SSL verification (not recommended for production) from huaweicloudsdkcore.http.http_config import HttpConfig config = HttpConfig.get_default_http_config() config.ignore_ssl_verification = True client = FunctionGraphClient.new_builder() \ .with_http_config(config) \ .with_credentials(credentials) \ .with_region(region) \ .build()Technical Analysis
The troubleshooting guide instructs users to set
ignore_ssl_verificationtoTrueon an authenticated Huawei Cloud SDK client. This disables validation of the remote server's TLS certificate while the client continues to use cloud credentials.The warning that the configuration is “not recommended for production” does not technically prevent its use. If a user follows this procedure to work around an SSL error, the client can accept a certificate presented by an untrusted network intermediary. This breaks the server-authentication boundary that TLS is intended to enforce.
Attack Path
- A user encounters a certificate error and applies the documented troubleshooting configuration.
- The user performs authenticated FunctionGraph API operations using the resulting client.
- An attacker with a network interception position, such as control over a proxy, gateway, or hostile network, presents an untrusted certificate.
- Because certificate verification is disabled, the SDK accepts the attacker's endpoint rather than rejecting the connection.
- The attacker can observe authenticated requests, manipulate API responses, and potentially replay captured valid requests where the service permits replay.
Impact Assessment
Exploitation requires a network-positioned attacker and a user who has enabled the documented bypass. The exposed scope i ...[truncated 448 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to disable TLS certificate verification.
- Direct users to repair the underlying trust configuration, such as installing the correct CA bundle, configuring an enterprise proxy CA, correcting the system clock, or updating the certificate store.
- Keep certificate verification enabled for every authenticated Huawei Cloud request.
- If an insecure connectivity diagnostic is unavoidable, isolate it from the authenticated SDK client, require an explicit opt-in, and prevent credentials or privileged API requests from being used during the test.
- Add documentation explaining that bypassing certificate validation permits endpoint impersonation and must not be used as a general SSL troubleshooting solution.
