Description
tls.Config{InsecureSkipVerify: true} disables default server certificate chain and hostname verification. Without correct alternative verification, the server's identity is not established.
Potential impact
- An attacker on the network path may intercept a connection using an invalid certificate.
- Sensitive requests and responses may be exposed or altered.
Remediation
- Keep default certificate verification enabled and correctly configure trusted CAs and the server's certificate.
- Use a
ServerNamematching the destination. If custom verification is necessary, correctly verify trust and the intended identity inVerifyConnectionor an equivalent mechanism. - Client authentication in mTLS does not replace server certificate verification. Keep test-only verification exceptions out of production code.
Examples
These excerpts show TLS client settings. The connection code must provide the correct destination hostname and trusted roots. A minimum TLS version alone does not establish the server's identity.
Before
go
cfg := &tls.Config{InsecureSkipVerify: true}
After
go
cfg := &tls.Config{MinVersion: tls.VersionTLS12}
Explanation:
- Before:
InsecureSkipVerify: truedisables default server certificate chain and hostname verification. - After: The configuration keeps the default
falsevalue forInsecureSkipVerifyand sets a minimum TLS version. Default certificate verification applies when the connection uses the correct hostname and trust settings.