Skip to content

[PSU-1420] fix(agent): use TLS for PSU gRPC over HTTPS - #2017

Merged
Marc-André Moreau (mamoreau-devolutions) merged 1 commit into
masterfrom
adamdriscoll-fix-agent-https-grpc
Sep 29, 2026
Merged

Marc-André Moreau (mamoreau-devolutions) merged 1 commit into
masterfrom
adamdriscoll-fix-agent-https-grpc

Conversation

@adamdriscoll

Copy link
Copy Markdown
Contributor

The Devolutions Agent can now register with PowerShell Universal over HTTPS. Previously, its gRPC client sent plaintext HTTP/2 to HTTPS endpoints because tonic TLS support was disabled and endpoint construction did not configure TLS from the URL. The connection now uses native certificate roots for HTTPS while retaining plaintext HTTP support.

A regression test reproduced the plaintext preface before the fix and verifies a TLS ClientHello afterward. All 76 Agent library tests and workspace Clippy pass. Against isolated PSU 2026.3.1.0, the locally built Linux Agent registered over trusted-certificate HTTPS; an untrusted certificate was rejected, and HTTP gRPC registration still worked. The full workspace test run could not pass on this Windows host: an unrelated example hit a linker file lock, and three package-broker reparse-point tests require a privilege this process lacks.

Issue: PSU-1420

The PSU agent sent plaintext HTTP/2 to HTTPS URLs because tonic lacked TLS support and from_shared did not configure it. Enable native-root TLS and construct the endpoint with scheme-aware configuration while keeping HTTP connections unchanged.

Issue: PSU-1420

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 29, 2026 20:01
@adamdriscoll

Copy link
Copy Markdown
Contributor Author

Implementation notes:

  • Enabled tonic native-root TLS and used its scheme-aware endpoint constructor, so HTTPS performs TLS negotiation and validates the server certificate; HTTP remains plaintext HTTP/2.
  • Selected the existing Agent rustls ring provider before creating the TLS endpoint because other dependencies enable multiple crypto providers.
  • Added a wire-level regression: before the fix the HTTPS client sent the HTTP/2 P byte; after the fix it starts a TLS ClientHello (0x16).
  • Verified PSU 2026.3.1.0 registration from the locally built Linux image with a trusted certificate and Agent-role token. An untrusted certificate was rejected, and HTTP registration still succeeded. No migration or insecure certificate override is required.
  • All 76 Agent library tests and workspace Clippy passed. The full workspace test run is limited by unrelated Windows example linker and package-broker privilege failures.

Note

LLM-assisted content (no human feedback).

@github-actions

Copy link
Copy Markdown

Let maintainers know that an action is required on their side

  • Add the label release-required Please cut a new release (Devolutions Gateway, Devolutions Agent, Jetsocat, PowerShell module) when you request a maintainer to cut a new release (Devolutions Gateway, Devolutions Agent, Jetsocat, PowerShell module)

  • Add the label release-blocker Follow-up is required before cutting a new release if a follow-up is required before cutting a new release

  • Add the label publish-required Please publish libraries (`Devolutions.Gateway.Utils`, OpenAPI clients, etc) when you request a maintainer to publish libraries (Devolutions.Gateway.Utils, OpenAPI clients, etc.)

  • Add the label publish-blocker Follow-up is required before publishing libraries if a follow-up is required before publishing libraries

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation correctly enables trusted TLS for HTTPS without regressing plaintext HTTP support.

Review effort: Balanced
Findings: None

What changed in this PR

Enables secure PSU gRPC registration over HTTPS while preserving HTTP compatibility.

Changes:

  • Enables tonic TLS with native certificate roots.
  • Builds scheme-aware PSU endpoints and adds protocol regression tests.
  • Documents HTTPS certificate trust requirements.
File Description
devolutions-agent/​Cargo.toml Enables tonic native-root TLS.
devolutions-agent/​src/​psu_agent/​mod.rs Configures HTTPS endpoints and tests TLS/HTTP behavior.
Cargo.lock Records new TLS dependencies.
package/​AgentLinux/​README.md Documents HTTPS container setup.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@mamoreau-devolutions
Marc-André Moreau (mamoreau-devolutions) merged commit d0f13ef into master Sep 29, 2026
48 checks passed
@mamoreau-devolutions
Marc-André Moreau (mamoreau-devolutions) deleted the adamdriscoll-fix-agent-https-grpc branch September 29, 2026 20:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants