Use certificate subject to get a public key of the TLS server
This commit is contained in:
+11
-7
@@ -462,6 +462,7 @@ static status_t send_key_exchange(private_tls_peer_t *this,
|
|||||||
tls_handshake_type_t *type, tls_writer_t *writer)
|
tls_handshake_type_t *type, tls_writer_t *writer)
|
||||||
{
|
{
|
||||||
public_key_t *public = NULL, *current;
|
public_key_t *public = NULL, *current;
|
||||||
|
certificate_t *cert;
|
||||||
enumerator_t *enumerator;
|
enumerator_t *enumerator;
|
||||||
auth_cfg_t *auth;
|
auth_cfg_t *auth;
|
||||||
rng_t *rng;
|
rng_t *rng;
|
||||||
@@ -482,15 +483,18 @@ static status_t send_key_exchange(private_tls_peer_t *this,
|
|||||||
chunk_from_thing(this->client_random),
|
chunk_from_thing(this->client_random),
|
||||||
chunk_from_thing(this->server_random));
|
chunk_from_thing(this->server_random));
|
||||||
|
|
||||||
enumerator = lib->credmgr->create_public_enumerator(lib->credmgr,
|
cert = this->server_auth->get(this->server_auth, AUTH_HELPER_SUBJECT_CERT);
|
||||||
KEY_ANY, this->server, this->server_auth);
|
if (cert)
|
||||||
while (enumerator->enumerate(enumerator, ¤t, &auth))
|
|
||||||
{
|
{
|
||||||
public = current->get_ref(current);
|
enumerator = lib->credmgr->create_public_enumerator(lib->credmgr,
|
||||||
break;
|
KEY_ANY, cert->get_subject(cert), this->server_auth);
|
||||||
|
while (enumerator->enumerate(enumerator, ¤t, &auth))
|
||||||
|
{
|
||||||
|
public = current->get_ref(current);
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
enumerator->destroy(enumerator);
|
||||||
}
|
}
|
||||||
enumerator->destroy(enumerator);
|
|
||||||
|
|
||||||
if (!public)
|
if (!public)
|
||||||
{
|
{
|
||||||
DBG1(DBG_IKE, "no TLS public key found for server '%Y'", this->server);
|
DBG1(DBG_IKE, "no TLS public key found for server '%Y'", this->server);
|
||||||
|
|||||||
Reference in New Issue
Block a user