diff options
| author | tb <> | 2024-08-03 04:50:27 +0000 |
|---|---|---|
| committer | tb <> | 2024-08-03 04:50:27 +0000 |
| commit | 7ffee9d08a91191b5a4fb21336efef092b583c3e (patch) | |
| tree | ab072a8587850bb026552dec2888fdf2051ad344 /src/lib/libssl/ssl_lib.c | |
| parent | bb27421ed2f49cdd9bf2ec374d8a42ff058d63a8 (diff) | |
| download | openbsd-7ffee9d08a91191b5a4fb21336efef092b583c3e.tar.gz openbsd-7ffee9d08a91191b5a4fb21336efef092b583c3e.tar.bz2 openbsd-7ffee9d08a91191b5a4fb21336efef092b583c3e.zip | |
Prepare to provide SSL_CTX_set1_cert_store()
SSL_CTX_set_cert_store() should have been called SSL_CTX_set0_cert_store()
since it takes ownership of the store argument. Apparently a few people ran
into the issue of not bumping the refcount themselves, leading to use after
frees about 10 years ago. This is a quite rarely used API and there are no
misuses in the ports tree, but since someone did the work of writing a diff,
we can still add it.
Needless to say that SSL_CTX_get_cert_store() obviously has the exact same
issue and nobody seems to have thought of adding a get0 or get1 version to
match...
Fixes https://github.com/libressl/openbsd/issues/71
From Kenjiro Nakayama
Diffstat (limited to 'src/lib/libssl/ssl_lib.c')
| -rw-r--r-- | src/lib/libssl/ssl_lib.c | 12 |
1 files changed, 11 insertions, 1 deletions
diff --git a/src/lib/libssl/ssl_lib.c b/src/lib/libssl/ssl_lib.c index 4cf5c46fda..1a2bf36952 100644 --- a/src/lib/libssl/ssl_lib.c +++ b/src/lib/libssl/ssl_lib.c | |||
| @@ -1,4 +1,4 @@ | |||
| 1 | /* $OpenBSD: ssl_lib.c,v 1.328 2024/07/20 04:04:23 jsing Exp $ */ | 1 | /* $OpenBSD: ssl_lib.c,v 1.329 2024/08/03 04:50:27 tb Exp $ */ |
| 2 | /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) | 2 | /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) |
| 3 | * All rights reserved. | 3 | * All rights reserved. |
| 4 | * | 4 | * |
| @@ -3403,6 +3403,16 @@ SSL_CTX_set_cert_store(SSL_CTX *ctx, X509_STORE *store) | |||
| 3403 | } | 3403 | } |
| 3404 | LSSL_ALIAS(SSL_CTX_set_cert_store); | 3404 | LSSL_ALIAS(SSL_CTX_set_cert_store); |
| 3405 | 3405 | ||
| 3406 | void | ||
| 3407 | SSL_CTX_set1_cert_store(SSL_CTX *ctx, X509_STORE *store) | ||
| 3408 | { | ||
| 3409 | if (store != NULL) | ||
| 3410 | X509_STORE_up_ref(store); | ||
| 3411 | |||
| 3412 | SSL_CTX_set_cert_store(ctx, store); | ||
| 3413 | } | ||
| 3414 | LSSL_ALIAS(SSL_CTX_set1_cert_store); | ||
| 3415 | |||
| 3406 | X509 * | 3416 | X509 * |
| 3407 | SSL_CTX_get0_certificate(const SSL_CTX *ctx) | 3417 | SSL_CTX_get0_certificate(const SSL_CTX *ctx) |
| 3408 | { | 3418 | { |
