<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/lib/libcrypto/x509, branch libressl-v3.5.1</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=libressl-v3.5.1</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=libressl-v3.5.1'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2022-03-13T17:23:02+00:00</updated>
<entry>
<title>Relax the check of x509_constraints_dirname()</title>
<updated>2022-03-13T17:23:02+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2022-03-13T17:23:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=80a47514c89065d34f61afd4698b0f8182c45d60'/>
<id>urn:sha1:80a47514c89065d34f61afd4698b0f8182c45d60</id>
<content type='text'>
The dirname constraint must be a prefix in DER format, so relax the
check from requiring equal-length strings to allow shorter names also.

From Alex Wilson

ok jsing
</content>
</entry>
<entry>
<title>Add x509_constraints_validate() to x509_internal.h</title>
<updated>2022-03-13T17:08:04+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2022-03-13T17:08:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=cd66e82e3090c8e0b602600f92762eec03e1f998'/>
<id>urn:sha1:cd66e82e3090c8e0b602600f92762eec03e1f998</id>
<content type='text'>
From Alex Wilson

ok jsing
</content>
</entry>
<entry>
<title>Check name constraints using the proper API</title>
<updated>2022-03-13T16:48:49+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2022-03-13T16:48:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=7bdf8508440bb6ad889ebb6210b36e2e45db8c79'/>
<id>urn:sha1:7bdf8508440bb6ad889ebb6210b36e2e45db8c79</id>
<content type='text'>
The previous versions were too strict and disallowed leading dots.

From Alex Wilson

ok jsing
</content>
</entry>
<entry>
<title>style tweak</title>
<updated>2022-03-13T16:30:31+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2022-03-13T16:30:31+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=6a05251669a841118ef2afb995c9fdf4ec6f7abf'/>
<id>urn:sha1:6a05251669a841118ef2afb995c9fdf4ec6f7abf</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Add missing error check after strdup()</title>
<updated>2022-03-13T16:25:58+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2022-03-13T16:25:58+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=eb5306b751b98d33dc4833a353cd77e6e3a9d3ad'/>
<id>urn:sha1:eb5306b751b98d33dc4833a353cd77e6e3a9d3ad</id>
<content type='text'>
From Alex Wilson

ok jsing
</content>
</entry>
<entry>
<title>Pull a len == 0 check up before malloc(len) to avoid implementation</title>
<updated>2022-03-03T11:29:05+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2022-03-03T11:29:05+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=4544eb8a42dcaaf2607c92148dc57fb8caa03aaf'/>
<id>urn:sha1:4544eb8a42dcaaf2607c92148dc57fb8caa03aaf</id>
<content type='text'>
defined behavior.

ok deraadt inoguchi
</content>
</entry>
<entry>
<title>Unwrap a line</title>
<updated>2022-03-02T17:53:03+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2022-03-02T17:53:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=e1b11278a865932b9b7f8f0b46d05df1424c98c6'/>
<id>urn:sha1:e1b11278a865932b9b7f8f0b46d05df1424c98c6</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Get rid of SHA1 for comparing CRL's - use SHA512 just like we do for certs.</title>
<updated>2022-02-24T22:05:07+00:00</updated>
<author>
<name>beck</name>
<email></email>
</author>
<published>2022-02-24T22:05:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=e29735531148d227a52ccd6fa19e0b2cdf8b7b83'/>
<id>urn:sha1:e29735531148d227a52ccd6fa19e0b2cdf8b7b83</id>
<content type='text'>
ok tb@
</content>
</entry>
<entry>
<title>Fix length check of IP addresses for name constraints</title>
<updated>2022-02-11T17:41:55+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2022-02-11T17:41:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=361c0710908fd1b1a377f83b3fd0ba3c3491c6bb'/>
<id>urn:sha1:361c0710908fd1b1a377f83b3fd0ba3c3491c6bb</id>
<content type='text'>
An IP address in a name constraint is actually an IP address concatenated
with a netmask, so it is twice as long as usual.

This fixes a third bug introduced in r1.3 and reported by Volker Schlecht

ok jsing
</content>
</entry>
<entry>
<title>Add missing error check for a2i_GENERAL_NAME()</title>
<updated>2022-02-11T17:39:36+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2022-02-11T17:39:36+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=911e0aa6f16aba90dc8107a37cd5e01f041fc86a'/>
<id>urn:sha1:911e0aa6f16aba90dc8107a37cd5e01f041fc86a</id>
<content type='text'>
Fixes a segfault reported by Volker Schlecht.

ok jsing
</content>
</entry>
</feed>
