Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
OpenHarmony
Third Party Openssl
提交
2b3936e8
T
Third Party Openssl
项目概览
OpenHarmony
/
Third Party Openssl
1 年多 前同步成功
通知
10
Star
18
Fork
1
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
T
Third Party Openssl
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
提交
Issue看板
提交
2b3936e8
编写于
12月 25, 2010
作者:
D
Dr. Stephen Henson
浏览文件
操作
浏览文件
下载
电子邮件补丁
差异文件
avoid verification loops in trusted store when path building
上级
c596b2ab
变更
4
隐藏空白更改
内联
并排
Showing
4 changed file
with
23 addition
and
0 deletion
+23
-0
CHANGES
CHANGES
+4
-0
crypto/x509/x509_txt.c
crypto/x509/x509_txt.c
+2
-0
crypto/x509/x509_vfy.c
crypto/x509/x509_vfy.c
+15
-0
crypto/x509/x509_vfy.h
crypto/x509/x509_vfy.h
+2
-0
未找到文件。
CHANGES
浏览文件 @
2b3936e8
...
...
@@ -4,6 +4,10 @@
Changes between 1.0.1 and 1.1.0 [xx XXX xxxx]
*) If a candidate issuer certificate is already part of the constructed
path ignore it: new debug notification X509_V_ERR_PATH_LOOP for this case.
[Steve Henson]
*) Improve forward-security support: add functions
void SSL_CTX_set_not_resumable_session_callback(SSL_CTX *ctx, int (*cb)(SSL *ssl, int is_forward_secure))
...
...
crypto/x509/x509_txt.c
浏览文件 @
2b3936e8
...
...
@@ -183,6 +183,8 @@ const char *X509_verify_cert_error_string(long n)
return
(
"unsupported or invalid name syntax"
);
case
X509_V_ERR_CRL_PATH_VALIDATION_ERROR
:
return
(
"CRL path validation error"
);
case
X509_V_ERR_PATH_LOOP
:
return
(
"Path Loop"
);
default:
BIO_snprintf
(
buf
,
sizeof
buf
,
"error number %ld"
,
n
);
...
...
crypto/x509/x509_vfy.c
浏览文件 @
2b3936e8
...
...
@@ -439,6 +439,21 @@ static int check_issued(X509_STORE_CTX *ctx, X509 *x, X509 *issuer)
{
int
ret
;
ret
=
X509_check_issued
(
issuer
,
x
);
if
(
ret
==
X509_V_OK
)
{
int
i
;
X509
*
ch
;
for
(
i
=
0
;
i
<
sk_X509_num
(
ctx
->
chain
);
i
++
)
{
ch
=
sk_X509_value
(
ctx
->
chain
,
i
);
if
(
ch
==
issuer
||
!
X509_cmp
(
ch
,
issuer
))
{
ret
=
X509_V_ERR_PATH_LOOP
;
break
;
}
}
}
if
(
ret
==
X509_V_OK
)
return
1
;
/* If we haven't asked for issuer errors don't set ctx */
...
...
crypto/x509/x509_vfy.h
浏览文件 @
2b3936e8
...
...
@@ -353,6 +353,8 @@ void X509_STORE_CTX_set_depth(X509_STORE_CTX *ctx, int depth);
#define X509_V_ERR_UNSUPPORTED_CONSTRAINT_SYNTAX 52
#define X509_V_ERR_UNSUPPORTED_NAME_SYNTAX 53
#define X509_V_ERR_CRL_PATH_VALIDATION_ERROR 54
/* Another issuer check debug option */
#define X509_V_ERR_PATH_LOOP 55
/* The application is not happy */
#define X509_V_ERR_APPLICATION_VERIFICATION 50
...
...
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录