summaryrefslogtreecommitdiff
path: root/src/lib/libcrypto/ecdsa/ecs_lib.c (unfollow)
Commit message (Collapse)AuthorFilesLines
2019-04-22Avoid potential double frees in i2v_AUTHORITY_KEYID(), i2v_GENERAL_NAME()tb2-6/+22
and i2v_GENERAL_NAMES() by taking ownership of the extlist only if we were passed NULL. Otherwise it remains the caller's responsibility to free it. To do so, we allocate the extlist explicitly instead of using X509V3_add_value()'s implicit allocation feature. Preserve behavior in i2v_AUTHORITY_KEYID() by adding an explicit check that something was pushed onto the stack. The other i2v_* functions will receive a similar treatment in upcoming commits. ok jsing
2019-04-22Provide a derr label (decode/decrypt error) in tls1_decrypt_ticket().jsing1-41/+29
This handles the ret = 2 case and makes the code more readable. ok tb@
2019-04-22Pass the session ID down to the session/ticket handling code as a CBS.jsing4-35/+36
Convert ssl_get_prev_session(), tls1_process_ticket() and tls1_decrypt_ticket() to handle the session ID from the client hello as a CBS. While here also swap the order of arguments for tls1_decrypt_ticket() so that it is consistent with the other functions. ok tb@
2019-04-22Inline and remove the tlsext_tick_md macro.jsing3-6/+5
There is not much point having a tlsext_tick_md macro that replaces EVP_sha256() in two places, when the cipher is just hardcoded. ok tb@
2019-04-21Add error checking to i2v_AUTHORITY_KEYID(), i2v_GENERAL_NAME()tb2-32/+80
and i2v_GENERAL_NAMES(). This fixes a couple of leaks and other ugliness. tweaks & ok jsing
2019-04-21The noop v2i_PKEY_USAGE_PERIOD() has been commented out since becktb1-14/+2
imported OpenSSL 0.9.4 in 1999. It won't ever be used.
2019-04-21Fix awful whitespace in OBJ_bsearch_ext()tb1-5/+6
2019-04-21KNF: use proper wrapping of function return type and nametb3-9/+9
2019-04-21Clean up tls1_process_ticket().jsing1-39/+43
We only have to find one extension, so do that first then proceed with processing and decryption. This makes the code more readable and drops two levels of indent. ok tb@
2019-04-21Cleanup more of tls_decrypt_ticket().jsing1-5/+9
Separate the malloc() check and EVP_DecryptUpdate() - the malloc() failure is fatal while a EVP_DecryptUpdate() is a decryption failure. Also ensure that we clear the error stack in all cases where we are indicating a failure to decrypt or decode the ticket - otherwise SSL_error() while later return failure when it should not. ok tb@
2019-04-21Start cleaning up tls_decrypt_ticket().jsing1-58/+63
Rather than returning from multiple places and trying to clean up as we go, move to a single exit point and clean/free in one place. Also invert the logic that handles NULL sessions - fail early, rather than having an indented if test for success. ok tb@
2019-04-21fix some style nits to reduce noise in an upcoming difftb1-9/+8
2019-04-20Avoid undefined behaviour that results from negating a signed long withjsing1-2/+2
minimum value. Fixes oss-fuzz #14354. ok beck@ bcook@ tb@
2019-04-19Allocate md_data with calloc to avoid use of uninitialised memory.jsing1-6/+6
Found by Guido Vranken when fuzzing and trying to use GOST with HMAC. Fix confirmed by Guido; ok tb@
2019-04-19Allocate fixed NIDs for SM3/SM4.jsing1-0/+12
2019-04-16Rewrite & fix X509V3_add_value()tb1-17/+24
X509V3_add_value() helpfully allocates a STACK_OF(CONF_VALUE) if it receives a pointer to a NULL pointer. If anything fails along the way, it is however the caller's responsibility to free it. This can easily be fixed by freeing *extlist in the error path and zeroing it to avoid a double free if there happens to be a caller out there that avoids the leak. Polish a few things so the function conforms a bit better to our usual style. tweak & ok jsing
2019-04-16indent err: labelstb1-7/+7
2019-04-16wrap an overlong line and kill a space before a tabtb1-3/+4
2019-04-16Move function types to their own lines; rewrap.tb1-30/+40
2019-04-15Avoid signed integer overflow.jsing1-2/+2
Fixes oss-fuzz issue #13843. ok tb@
2019-04-14Add input validation to BIO_read()/BIO_write().jsing1-4/+14
Some bread/bwrite functions implement this themselves, while others do not. This makes it consistent across all BIO implementations. Addresses an issue that Guido Vranken found with his fuzzer. ok tb@
2019-04-14Some more malloc() to calloc() conversions.jsing1-7/+5
ok tb@
2019-04-14Remove two pointless chunks of code.jsing1-16/+1
This reverts part of OpenSSL c2fd5d79, which added the same code to AES CCM, GCM and XTS. In the case of CCM and GCM nothing assigns {ccm,gcm}.key so there is never going to be anything to update (unlike XTS). ok tb@
2019-04-14Use calloc() when allocating cipher_data.jsing1-5/+5
Avoids use of uninitialised memory. ok tb@
2019-04-14Annotate a future improvement.jsing1-1/+2
2019-04-14Avoid potential double-frees following EVP_CIPHER_CTX_copy().jsing1-4/+17
In the case of a cipher with a custom copy control, if that control fails we may still have pointers that we do not own in the previously copied cipher data. Avoid potential double-frees by zeroing and freeing the copied cipher data in this case. Issue reported by Guido Vranken. ok tb@
2019-04-14Fix previous: I forgot to rename the bn_to_string() prototype.tb1-2/+2
2019-04-13Add a test for the bn_to_string() function introduced in v3_utl.c r1.32.tb2-6/+133
2019-04-13Null out pointers on asprintf() failure.tb1-3/+7
These pointers will be passed to free. According to asprintf(3), "on OpenBSD, ret will be set to the null pointer, but this behavior should not be relied upon." ok jsing
2019-04-13Avoid quadratic behavior of decimal BIGNUM conversiontb1-9/+36
The complexity of BN_bn2dec(bn) is quadratic in the length of bn. This function is used for printing numbers in CRLs which are typically small. If a BN is larger than 127 bits, dump it as hex because that's cheap and for numbers this size not significantly harder for humans to parse. OpenSSL commit 10a3195fcf7d04ba519651cf12e945a8fe470a3c by David Benjamin (still under the old licence), but significantly simplified. Ideally, we would catch excessively large numbers on deserialization, but that is made trickier by the templated ASN1. Erroring out is also not an option since the relevant part of the x509v3/ directory doesn't like to do proper error checking (looking at you v2i and i2v). Timeout found by oss-fuzz, should fix issues #13823 and #14130. input & ok jsing
2019-04-13Avoid leak in SSL_dup_CA_list()tb1-8/+14
In the case that X509_NAME_dup() succeeds, but sk_X509_NAME_push() fails, name is leaked. The entire function is trying to be clever and therefore hard to follow. Let's do it the stupid but safe way. ok jsing
2019-04-10Avoid an overread caused by d2i_PrivateKey().jsing1-1/+3
There are cases where the old_priv_decode() function can fail but consume bytes. This will result in the pp pointer being advanced, which causes d2i_PKCS8_PRIV_KEY_INFO() to be called with an advanced pointer and incorrect length. Fixes oss-fuzz #13803 and #14142. ok deraadt@ tb@
2019-04-09Recommend SSL_CTX_add1_chain_cert(3) rather thanschwarze1-12/+11
SSL_CTX_add_extra_chain_cert(3). From Dr. Stephen Henson <steve at openssl dot org> via OpenSSL commit a4339ea3 Jan 3 22:38:03 2014 +0000 which is still under a free license.
2019-04-09Document SSL_CTX_clear_mode(3) and SSL_clear_mode(3).schwarze1-22/+48
From Kurt Roeckx <kurt at roeckx dot be> via OpenSSL commit 57fd5170 May 13 11:24:11 2018 +0200 which is still under a free license. While here, polish awkward wording and reduce duplication.
2019-04-07exitting -> exitingtb1-1/+1
From Michael Scovetta, PR #108
2019-04-07Revert tasn_prn.c r1.18.jsing1-6/+2
In this code, just because something is cast to a type doesn't mean it is necessarily that type - in this case we cannot check the length of the ASN1_STRING here, since it might be another data type and later handled as an int (for example, in the V_ASN1_BOOLEAN case). We will revisit this post release. ok tb@
2019-04-05whitespace consistencytb1-1/+2
2019-04-05Add SERVER_HELLO_RETRY statetb1-1/+7
2019-04-05By design, our state machine is a DAG contrary to the state machine intb4-7/+29
the spec. To avoid the obvious loop in the RFC's state machine, we added a CLIENT_HELLO_RETRY state which is a second ClientHello with special rules. There is, however, no state to react to this second client hello. This adds a matching SERVER_HELLO_RETRY state to the handshakes table. This means in particular that the WITH_HRR state cannot be set in tls13_server_hello_recv(), so remove this now dead check. ok jsing
2019-04-05Import SSL_CTX_add1_chain_cert(3) from OpenSSL branch 1.1.1, which is stillschwarze5-17/+264
under a free license, omitting functions we don't have and tweaked by me; the functions were provided by jsing@ in ssl.h rev. 1.166. While here, also document SSL_CTX_get_extra_chain_certs(3) because it is closely related to companion functions are already documented and the API is kind of incomplete without it.
2019-04-05Zap two dead #defines that were unused since jsing deleted thetb1-5/+1
record_type member of the tls13_handshake_action struct. ok jsing
2019-04-04I forgot to mark some targets as .PHONYtb1-1/+5
2019-04-04Implement legacy fallback for the TLS 1.3 client.jsing3-8/+87
If the Server Hello received indicates that the server did not negotiate TLS 1.3, fallback to the original TLS client implementation. ok bcook@, tb@
2019-04-04Clean up the cipher/digest table mess.jsing3-179/+45
The original implementation allows for libcrypto to be compiled without a given algorithm and libssl then detects that ciphers or digests are unavailable so that it can disable the associated cipher suites. This is unnecessary since we do not compile out algorithms. ok beck@, tb@ (a while back)
2019-04-04Use correct define.jsing1-2/+2
2019-04-04Only assign destlen when src is non-NULL.jsing1-3/+4
This avoids ever having a non-zero len with a NULL pointer.
2019-04-04Switch to pthread_mutex_init().jsing1-3/+5
While PTHREAD_MUTEX_INITIALIZER can be used on OpenBSD, some other platforms do not like it. Noted by bcook@
2019-04-04Bump libssl/libtls minors due to symbol addition.jsing2-2/+2
2019-04-04Provide SSL chain/cert chain APIs.jsing3-2/+161
These allow for chains to be managed on a per-certificate basis rather than as a single "extra certificates" list. Note that "chain" in this context does not actually include the leaf certificate however, unlike SSL_CTX_use_certificate_chain_{file,mem}(). Thanks to sthen@ for running this through a bulk ports build. ok beck@ tb@
2019-04-04This case also needs to be fatal.jsing1-1/+2