openssl: Support certificates with Ed25519/448 keys
This commit is contained in:
@@ -1088,6 +1088,7 @@ static bool parse_certificate(private_openssl_x509_t *this)
|
|||||||
#else
|
#else
|
||||||
X509_ALGOR *alg;
|
X509_ALGOR *alg;
|
||||||
#endif
|
#endif
|
||||||
|
key_type_t ed_type = KEY_ED448;
|
||||||
|
|
||||||
this->x509 = d2i_X509(NULL, &ptr, this->encoding.len);
|
this->x509 = d2i_X509(NULL, &ptr, this->encoding.len);
|
||||||
if (!this->x509)
|
if (!this->x509)
|
||||||
@@ -1130,6 +1131,17 @@ static bool parse_certificate(private_openssl_x509_t *this)
|
|||||||
chunk, BUILD_END);
|
chunk, BUILD_END);
|
||||||
free(chunk.ptr);
|
free(chunk.ptr);
|
||||||
break;
|
break;
|
||||||
|
case OID_ED25519:
|
||||||
|
ed_type = KEY_ED25519;
|
||||||
|
/* fall-through */
|
||||||
|
case OID_ED448:
|
||||||
|
/* for EdDSA, the parsers expect the full subjectPublicKeyInfo */
|
||||||
|
chunk = openssl_i2chunk(X509_PUBKEY, X509_get_X509_PUBKEY(this->x509));
|
||||||
|
this->pubkey = lib->creds->create(lib->creds,
|
||||||
|
CRED_PUBLIC_KEY, ed_type, BUILD_BLOB_ASN1_DER,
|
||||||
|
chunk, BUILD_END);
|
||||||
|
free(chunk.ptr);
|
||||||
|
break;
|
||||||
default:
|
default:
|
||||||
DBG1(DBG_LIB, "unsupported public key algorithm");
|
DBG1(DBG_LIB, "unsupported public key algorithm");
|
||||||
break;
|
break;
|
||||||
|
|||||||
Reference in New Issue
Block a user