Verify trustchain for each candidate certificate only once
This commit is contained in:
@@ -656,6 +656,14 @@ static bool verify_trust_chain(private_credential_manager_t *this,
|
|||||||
return trusted;
|
return trusted;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* List find match function for certificates
|
||||||
|
*/
|
||||||
|
static bool cert_equals(certificate_t *a, certificate_t *b)
|
||||||
|
{
|
||||||
|
return a->equals(a, b);
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* enumerator for trusted certificates
|
* enumerator for trusted certificates
|
||||||
*/
|
*/
|
||||||
@@ -676,6 +684,8 @@ typedef struct {
|
|||||||
certificate_t *pretrusted;
|
certificate_t *pretrusted;
|
||||||
/** currently enumerating auth config */
|
/** currently enumerating auth config */
|
||||||
auth_cfg_t *auth;
|
auth_cfg_t *auth;
|
||||||
|
/** list of failed candidates */
|
||||||
|
linked_list_t *failed;
|
||||||
} trusted_enumerator_t;
|
} trusted_enumerator_t;
|
||||||
|
|
||||||
METHOD(enumerator_t, trusted_enumerate, bool,
|
METHOD(enumerator_t, trusted_enumerate, bool,
|
||||||
@@ -723,6 +733,12 @@ METHOD(enumerator_t, trusted_enumerate, bool,
|
|||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (this->failed->find_first(this->failed, (void*)cert_equals,
|
||||||
|
NULL, current) == SUCCESS)
|
||||||
|
{ /* check each candidate only once */
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
DBG1(DBG_CFG, " using certificate \"%Y\"",
|
DBG1(DBG_CFG, " using certificate \"%Y\"",
|
||||||
current->get_subject(current));
|
current->get_subject(current));
|
||||||
if (verify_trust_chain(this->this, current, this->auth, FALSE,
|
if (verify_trust_chain(this->this, current, this->auth, FALSE,
|
||||||
@@ -735,6 +751,7 @@ METHOD(enumerator_t, trusted_enumerate, bool,
|
|||||||
}
|
}
|
||||||
return TRUE;
|
return TRUE;
|
||||||
}
|
}
|
||||||
|
this->failed->insert_last(this->failed, current->get_ref(current));
|
||||||
}
|
}
|
||||||
return FALSE;
|
return FALSE;
|
||||||
}
|
}
|
||||||
@@ -745,6 +762,7 @@ METHOD(enumerator_t, trusted_destroy, void,
|
|||||||
DESTROY_IF(this->pretrusted);
|
DESTROY_IF(this->pretrusted);
|
||||||
DESTROY_IF(this->auth);
|
DESTROY_IF(this->auth);
|
||||||
DESTROY_IF(this->candidates);
|
DESTROY_IF(this->candidates);
|
||||||
|
this->failed->destroy_offset(this->failed, offsetof(certificate_t, destroy));
|
||||||
free(this);
|
free(this);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -763,6 +781,7 @@ METHOD(credential_manager_t, create_trusted_enumerator, enumerator_t*,
|
|||||||
.type = type,
|
.type = type,
|
||||||
.id = id,
|
.id = id,
|
||||||
.online = online,
|
.online = online,
|
||||||
|
.failed = linked_list_create(),
|
||||||
);
|
);
|
||||||
return &enumerator->public;
|
return &enumerator->public;
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user