# AWS.Client security advisory

**URL:** https://forum.ada-lang.io/t/aws-client-security-advisory/1884
**Category:** General
**Created:** [March 13, 2025, 9:20pm UTC](https://forum.ada-lang.io/t/aws-client-security-advisory/1884 "2025-03-13T21:20:28Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![JeremyGrosser](https://forum.ada-lang.io/user_avatar/forum.ada-lang.io/jeremygrosser/32/3_2.png) [@JeremyGrosser](https://forum.ada-lang.io/u/JeremyGrosser)
#### Post date: [March 13, 2025, 9:20pm UTC](https://forum.ada-lang.io/t/aws-client-security-advisory/1884/1 "2025-03-13T21:20:28Z")

</div>

CVE-2024-55581

When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server’s certificate (unless the using program specifies a TLS configuration).

> **[CVE -
CVE-2024-55581](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-55581)**
>
> The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.

> **[SEC.AWS-0056-v1.pdf](https://docs.adacore.com/corp/security-advisories/SEC.AWS-0056-v1.pdf)**
>
> 178.37 KB

---

<div class="post-metadata">

### Author: ![OneWingedShark](https://forum.ada-lang.io/user_avatar/forum.ada-lang.io/onewingedshark/32/305_2.png) [@OneWingedShark](https://forum.ada-lang.io/u/OneWingedShark)
#### Post date: [March 14, 2025, 9:58pm UTC](https://forum.ada-lang.io/t/aws-client-security-advisory/1884/2 "2025-03-14T21:58:27Z")

</div>

> [@JeremyGrosser](#):
>
> When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS

That reminds me, I’d like to do a Ada/SPARK TLS implementation… but the best way to do that is an Ada/SPARK proved implementation of ASN.1. (The security certificate is, itself, an ASN.1 object, encoded with BER, if memory serves.)

---

<div class="post-metadata">

### Author: ![dmitry-kazakov](https://forum.ada-lang.io/user_avatar/forum.ada-lang.io/dmitry-kazakov/32/522_2.png) [@dmitry-kazakov](https://forum.ada-lang.io/u/dmitry-kazakov)
#### Post date: [March 15, 2025, 9:15am UTC](https://forum.ada-lang.io/t/aws-client-security-advisory/1884/3 "2025-03-15T09:15:41Z")

</div>

I take my hat off. ASN.1 is sheer horror. Though I do not understand the problem, if client allows desired settings just do it.

---

<div class="post-metadata">

### Author: ![sbenitezb](https://forum.ada-lang.io/user_avatar/forum.ada-lang.io/sbenitezb/32/285_2.png) [@sbenitezb](https://forum.ada-lang.io/u/sbenitezb)
#### Post date: [May 9, 2025, 6:14pm UTC](https://forum.ada-lang.io/t/aws-client-security-advisory/1884/4 "2025-05-09T18:14:06Z")

</div>

There’s asn1scc compiler that generates SPARK code.

---

<div class="post-metadata">

### Author: ![docandrew](https://forum.ada-lang.io/user_avatar/forum.ada-lang.io/docandrew/32/396_2.png) [@docandrew](https://forum.ada-lang.io/u/docandrew)
#### Post date: [May 12, 2025, 8:48pm UTC](https://forum.ada-lang.io/t/aws-client-security-advisory/1884/5 "2025-05-12T20:48:56Z")

</div>

I’ve been working on that here if you’re interested: [GitHub - docandrew/SPARKx509: Verified library for X.509 certificates](https://github.com/docandrew/sparkx509). I’m not convinced my approach is the best way about it but I can do some basic certificate parsing with it.

---

<div class="post-metadata">

### Author: ![docandrew](https://forum.ada-lang.io/user_avatar/forum.ada-lang.io/docandrew/32/396_2.png) [@docandrew](https://forum.ada-lang.io/u/docandrew)
#### Post date: [May 12, 2025, 8:49pm UTC](https://forum.ada-lang.io/t/aws-client-security-advisory/1884/6 "2025-05-12T20:49:31Z")

</div>

I took a look at this tool, unfortunately is isn’t capable of handling many of the datatypes used in the x509 RFCs.

---

<div class="post-metadata">

### Author: ![OneWingedShark](https://forum.ada-lang.io/user_avatar/forum.ada-lang.io/onewingedshark/32/305_2.png) [@OneWingedShark](https://forum.ada-lang.io/u/OneWingedShark)
#### Post date: [May 13, 2025, 5:05am UTC](https://forum.ada-lang.io/t/aws-client-security-advisory/1884/7 "2025-05-13T05:05:59Z")

</div>

> [@sbenitezb](#):
>
> There’s asn1scc compiler that generates SPARK code.

I think that’s backwards from what I was saying: implement ASN.1 in Ada/SPARK, not use ASN.1 to produce Ada/SPARK.

> [@docandrew](#):
>
> I took a look at this tool, unfortunately is isn’t capable of handling many of the datatypes used in the x509 RFCs.

Hence why (in my estimation) it would be better to implement ASN.1 itself within Ada/SPARK: establishing the data-structures (i.e. the meta-object system), and _then_ implementing the serialization/deserialization algorithms: going about this way, since you get the [meta]objects up and proven, then the production (stream-in & stream-out) of those objects proven, you would then have a system where X.509 certification is merely (a) defining the structure object data-structure, & (b) enforcing any additional constraints. (Also, this route gives you a solid, proven ASN.1 implementation that you can use for all other ASN.1-using projects/systems.)

That’s the benefit of the method; the drawback is that it is the up-front implementation of the ASN.1 standard, all of it, which is a lot of work.

> [@docandrew](#):
>
> I’ve been working on that here if you’re interested

> [@docandrew](#):
>
> I’m not convinced my approach is the best way about it but I can do some basic certificate parsing with it.

Cool!  
I’m glad you have some initial results; it’s really satisfying to see progress sometimes.  
I can’t promise I’ll get around to looking/poking any time soon, but I did want to give a little encouragement: Good job!

And it’s ok even if your current design isn’t the best, so long as you are learning. (That’s the point of experimenting.) It’s the engineering of a solution that needs to be “the best”, so you can allow yourself to “flail” a bit in your explorations.

---

<div class="post-metadata">

### Author: ![dmitry-kazakov](https://forum.ada-lang.io/user_avatar/forum.ada-lang.io/dmitry-kazakov/32/522_2.png) [@dmitry-kazakov](https://forum.ada-lang.io/u/dmitry-kazakov)
#### Post date: [May 13, 2025, 7:26am UTC](https://forum.ada-lang.io/t/aws-client-security-advisory/1884/8 "2025-05-13T07:26:12Z")

</div>

> [@docandrew](#):
>
> I took a look at this tool, unfortunately is isn’t capable of handling many of the datatypes used in the x509 RFCs.

Simple Components contains a full Ada implementation of ASN.1. X.509 certificates are provided as one of examples. [See](https://www.dmitry-kazakov.de/ada/components.htm#17.18.19).
