Repository navigation
use the SAN type tag in Mbed TLS verify_hostname and get_cert_sans - #2614
Merged
Merged
Conversation
Mbed TLS keeps a subjectAltName entry's GeneralName tag in buf.tag and the bare value in buf.p / buf.len. verify_hostname ignored the tag, so a dNSName whose bytes equal an address authenticated that IP host, and an iPAddress or rfc822Name was matched as a DNS pattern. get_cert_sans looked for the tag inside the value, so it reported no entries for an ordinary certificate, or part of a dNSName as an entry of its own.
Owner
|
Thanks! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
SAN entry type ignored in the Mbed TLS backend
Mbed TLS keeps a SAN entry's GeneralName tag in
buf.tagand only the bare value inbuf.p/buf.len, butverify_hostname()never reads the tag andget_cert_sans()looks for it inside the value, so a certificate for the dNSNamea.zz(bytes61 2e 7a 7a) authenticateshttps://97.46.122.122/, an iPAddress42.46.122.122is matched bycheck_hostname()as the DNS pattern*.zz, andsans()comes back empty for an ordinary certificate. Both now take the type frombuf.tag, which should bring them in line with the OpenSSL and wolfSSL backends; the two added tests fail on Mbed TLS 2.28, 3.6 and 4.2 without the change and pass on OpenSSL, Mbed TLS and wolfSSL with it.