TLS certificate verification disabled

TLS certificate verification disabled

Description

tls.Config{InsecureSkipVerify: true} disables default server certificate chain and hostname verification. Without correct alternative verification, the server's identity is not established.

Potential impact

  • An attacker on the network path may intercept a connection using an invalid certificate.
  • Sensitive requests and responses may be exposed or altered.

Remediation

  • Keep default certificate verification enabled and correctly configure trusted CAs and the server's certificate.
  • Use a ServerName matching the destination. If custom verification is necessary, correctly verify trust and the intended identity in VerifyConnection or an equivalent mechanism.
  • Client authentication in mTLS does not replace server certificate verification. Keep test-only verification exceptions out of production code.

Examples

These excerpts show TLS client settings. The connection code must provide the correct destination hostname and trusted roots. A minimum TLS version alone does not establish the server's identity.

Before

go
cfg := &tls.Config{InsecureSkipVerify: true}

After

go
cfg := &tls.Config{MinVersion: tls.VersionTLS12}

Explanation:

  • Before: InsecureSkipVerify: true disables default server certificate chain and hostname verification.
  • After: The configuration keeps the default false value for InsecureSkipVerify and sets a minimum TLS version. Default certificate verification applies when the connection uses the correct hostname and trust settings.

References