Skip to content

use the SAN type tag in Mbed TLS verify_hostname and get_cert_sans - #2614

Merged
yhirose merged 2 commits into
yhirose:masterfrom
metsw24-max:mbedtls-san-type-tag
Oct 6, 2026
Merged

yhirose merged 2 commits into
yhirose:masterfrom
metsw24-max:mbedtls-san-type-tag

Conversation

@metsw24-max

Copy link
Copy Markdown
Contributor

SAN entry type ignored in the Mbed TLS backend

Mbed TLS keeps a SAN entry's GeneralName tag in buf.tag and only the bare value in buf.p/buf.len, but verify_hostname() never reads the tag and get_cert_sans() looks for it inside the value, so a certificate for the dNSName a.zz (bytes 61 2e 7a 7a) authenticates https://97.46.122.122/, an iPAddress 42.46.122.122 is matched by check_hostname() as the DNS pattern *.zz, and sans() comes back empty for an ordinary certificate. Both now take the type from buf.tag, which should bring them in line with the OpenSSL and wolfSSL backends; the two added tests fail on Mbed TLS 2.28, 3.6 and 4.2 without the change and pass on OpenSSL, Mbed TLS and wolfSSL with it.

metsw24-max and others added 2 commits October 5, 2026 17:44
Mbed TLS keeps a subjectAltName entry's GeneralName tag in buf.tag and the bare value in buf.p / buf.len. verify_hostname ignored the tag, so a dNSName whose bytes equal an address authenticated that IP host, and an iPAddress or rfc822Name was matched as a DNS pattern. get_cert_sans looked for the tag inside the value, so it reported no entries for an ordinary certificate, or part of a dNSName as an entry of its own.
@yhirose
yhirose merged commit edc9760 into yhirose:master Oct 6, 2026
27 of 28 checks passed
@yhirose

yhirose commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants