• D
    crypto: add sanity checking of TLS x509 credentials · 9a2fd434
    Daniel P. Berrange 提交于
    If the administrator incorrectly sets up their x509 certificates,
    the errors seen at runtime during connection attempts are very
    obscure and difficult to diagnose. This has been a particular
    problem for people using openssl to generate their certificates
    instead of the gnutls certtool, because the openssl tools don't
    turn on the various x509 extensions that gnutls expects to be
    present by default.
    
    This change thus adds support in the TLS credentials object to
    sanity check the certificates when QEMU first loads them. This
    gives the administrator immediate feedback for the majority of
    common configuration mistakes, reducing the pain involved in
    setting up TLS. The code is derived from equivalent code that
    has been part of libvirt's TLS support and has been seen to be
    valuable in assisting admins.
    
    It is possible to disable the sanity checking, however, via
    the new 'sanity-check' property on the tls-creds object type,
    with a value of 'no'.
    
    Unit tests are included in this change to verify the correctness
    of the sanity checking code in all the key scenarios it is
    intended to cope with. As part of the test suite, the pkix_asn1_tab.c
    from gnutls is imported. This file is intentionally copied from the
    (long since obsolete) gnutls 1.6.3 source tree, since that version
    was still under GPLv2+, rather than the GPLv3+ of gnutls >= 2.0.
    Signed-off-by: NDaniel P. Berrange <berrange@redhat.com>
    9a2fd434
.gitignore 830 字节