x509: Consider authorityKeyIdentifier in issued_by()
Prior to verifying the cryptographic signature, check if the authorityKeyIdentifier matches the key ID of the issuing certificate if it is available.
This commit is contained in:
committed by
Tobias Brunner
parent
97c9158378
commit
027c5c9dcb
@@ -1710,6 +1710,7 @@ METHOD(certificate_t, issued_by, bool,
|
|||||||
public_key_t *key;
|
public_key_t *key;
|
||||||
bool valid;
|
bool valid;
|
||||||
x509_t *x509 = (x509_t*)issuer;
|
x509_t *x509 = (x509_t*)issuer;
|
||||||
|
chunk_t keyid = chunk_empty;
|
||||||
|
|
||||||
if (&this->public.interface.interface == issuer)
|
if (&this->public.interface.interface == issuer)
|
||||||
{
|
{
|
||||||
@@ -1733,9 +1734,22 @@ METHOD(certificate_t, issued_by, bool,
|
|||||||
return FALSE;
|
return FALSE;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if (!this->issuer->equals(this->issuer, issuer->get_subject(issuer)))
|
|
||||||
|
/* compare keyIdentifiers if available, otherwise use DNs */
|
||||||
|
if (this->authKeyIdentifier.ptr)
|
||||||
{
|
{
|
||||||
return FALSE;
|
keyid = x509->get_subjectKeyIdentifier(x509);
|
||||||
|
if (keyid.len && !chunk_equals(keyid, this->authKeyIdentifier))
|
||||||
|
{
|
||||||
|
return FALSE;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (!keyid.len)
|
||||||
|
{
|
||||||
|
if (!this->issuer->equals(this->issuer, issuer->get_subject(issuer)))
|
||||||
|
{
|
||||||
|
return FALSE;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/* get the public key of the issuer */
|
/* get the public key of the issuer */
|
||||||
|
|||||||
Reference in New Issue
Block a user