Latest update (add quic)
This commit is contained in:
+1
-20
@@ -461,25 +461,6 @@ int OSSL_CRMF_MSG_create_popo(OSSL_CRMF_MSG *crm, EVP_PKEY *pkey,
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* returns 0 for equal, -1 for a < b or error on a, 1 for a > b or error on b */
|
||||
static int X509_PUBKEY_cmp(X509_PUBKEY *a, X509_PUBKEY *b)
|
||||
{
|
||||
X509_ALGOR *algA = NULL, *algB = NULL;
|
||||
int res = 0;
|
||||
|
||||
if (a == b)
|
||||
return 0;
|
||||
if (a == NULL || !X509_PUBKEY_get0_param(NULL, NULL, NULL, &algA, a)
|
||||
|| algA == NULL)
|
||||
return -1;
|
||||
if (b == NULL || !X509_PUBKEY_get0_param(NULL, NULL, NULL, &algB, b)
|
||||
|| algB == NULL)
|
||||
return 1;
|
||||
if ((res = X509_ALGOR_cmp(algA, algB)) != 0)
|
||||
return res;
|
||||
return EVP_PKEY_cmp(X509_PUBKEY_get0(a), X509_PUBKEY_get0(b));
|
||||
}
|
||||
|
||||
/* verifies the Proof-of-Possession of the request with the given rid in reqs */
|
||||
int OSSL_CRMF_MSGS_verify_popo(const OSSL_CRMF_MSGS *reqs,
|
||||
int rid, int acceptRAVerified)
|
||||
@@ -522,7 +503,7 @@ int OSSL_CRMF_MSGS_verify_popo(const OSSL_CRMF_MSGS *reqs,
|
||||
CRMFerr(0, CRMF_R_POPO_MISSING_PUBLIC_KEY);
|
||||
return 0;
|
||||
}
|
||||
if (X509_PUBKEY_cmp(pubkey, sig->poposkInput->publicKey) != 0) {
|
||||
if (X509_PUBKEY_eq(pubkey, sig->poposkInput->publicKey) != 1) {
|
||||
CRMFerr(0, CRMF_R_POPO_INCONSISTENT_PUBLIC_KEY);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -108,7 +108,6 @@ struct ossl_crmf_certid_st {
|
||||
GENERAL_NAME *issuer;
|
||||
ASN1_INTEGER *serialNumber;
|
||||
} /* OSSL_CRMF_CERTID */;
|
||||
DECLARE_ASN1_DUP_FUNCTION(OSSL_CRMF_CERTID)
|
||||
|
||||
/*-
|
||||
* SinglePubInfo ::= SEQUENCE {
|
||||
|
||||
@@ -202,8 +202,8 @@ int OSSL_CRMF_pbm_new(const OSSL_CRMF_PBMPARAMETER *pbmp,
|
||||
macparams[1] = OSSL_PARAM_construct_octet_string(OSSL_MAC_PARAM_KEY,
|
||||
basekey, bklen);
|
||||
if ((mac = EVP_MAC_fetch(NULL, "HMAC", NULL)) == NULL
|
||||
|| (mctx = EVP_MAC_CTX_new(mac)) == NULL
|
||||
|| !EVP_MAC_CTX_set_params(mctx, macparams)
|
||||
|| (mctx = EVP_MAC_new_ctx(mac)) == NULL
|
||||
|| !EVP_MAC_set_ctx_params(mctx, macparams)
|
||||
|| !EVP_MAC_init(mctx)
|
||||
|| !EVP_MAC_update(mctx, msg, msglen)
|
||||
|| !EVP_MAC_final(mctx, mac_res, outlen, EVP_MAX_MD_SIZE))
|
||||
@@ -214,7 +214,7 @@ int OSSL_CRMF_pbm_new(const OSSL_CRMF_PBMPARAMETER *pbmp,
|
||||
err:
|
||||
/* cleanup */
|
||||
OPENSSL_cleanse(basekey, bklen);
|
||||
EVP_MAC_CTX_free(mctx);
|
||||
EVP_MAC_free_ctx(mctx);
|
||||
EVP_MAC_free(mac);
|
||||
EVP_MD_CTX_free(ctx);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user