mirror of https://github.com/wolfSSL/wolfssh.git
update client macro guard and add small stack dcert
parent
9e3c2f3b78
commit
0f9304d70d
|
|
@ -747,42 +747,64 @@ static int RequestAuthentication(WS_UserAuthData* authData,
|
|||
#ifdef WOLFSSL_FPKI
|
||||
/* compare user name to UPN in certificate */
|
||||
if (authData->sf.publicKey.isCert) {
|
||||
DecodedCert dCert;
|
||||
DecodedCert* dCert;
|
||||
#ifdef WOLFSSH_SMALL_STACK
|
||||
dCert = (DecodedCert*)WMALLOC(sizeof(DecodedCert), NULL,
|
||||
DYNTYPE_CERT);
|
||||
#else
|
||||
DecodedCert sdCert;
|
||||
dCert = &sdCert;
|
||||
#endif
|
||||
|
||||
wc_InitDecodedCert(&dCert, authData->sf.publicKey.publicKey,
|
||||
authData->sf.publicKey.publicKeySz, NULL);
|
||||
if (wc_ParseCert(&dCert, CERT_TYPE, NO_VERIFY, NULL) != 0) {
|
||||
wolfSSH_Log(WS_LOG_ERROR, "[SSHD] Unable to parse peer cert.");
|
||||
if (dCert == NULL) {
|
||||
wolfSSH_Log(WS_LOG_ERROR, "[SSHD] Error creating cert struct");
|
||||
ret = WOLFSSH_USERAUTH_INVALID_PUBLICKEY;
|
||||
}
|
||||
else {
|
||||
int usrMatch = 0;
|
||||
DNS_entry* current = dCert.altNames;
|
||||
|
||||
while (current != NULL) {
|
||||
if (current->type == ASN_OTHER_TYPE &&
|
||||
current->oidSum == UPN_OID) {
|
||||
/* found UPN oid, check name against user */
|
||||
int idx;
|
||||
|
||||
for (idx = 0; idx < current->len; idx++) {
|
||||
if (current->name[idx] == '@') break;
|
||||
}
|
||||
|
||||
if ((int)XSTRLEN(usr) == idx &&
|
||||
XSTRNCMP(usr, current->name, idx) == 0) {
|
||||
usrMatch = 1;
|
||||
}
|
||||
}
|
||||
current = current->next;
|
||||
}
|
||||
|
||||
if (usrMatch == 0) {
|
||||
wolfSSH_Log(WS_LOG_ERROR, "[SSHD] incorrect user cert sent");
|
||||
wc_InitDecodedCert(dCert, authData->sf.publicKey.publicKey,
|
||||
authData->sf.publicKey.publicKeySz, NULL);
|
||||
if (wc_ParseCert(dCert, CERT_TYPE, NO_VERIFY, NULL) != 0) {
|
||||
wolfSSH_Log(WS_LOG_ERROR, "[SSHD] Unable to parse peer "
|
||||
"cert.");
|
||||
ret = WOLFSSH_USERAUTH_INVALID_PUBLICKEY;
|
||||
}
|
||||
else {
|
||||
int usrMatch = 0;
|
||||
DNS_entry* current = dCert->altNames;
|
||||
|
||||
while (current != NULL) {
|
||||
if (current->type == ASN_OTHER_TYPE &&
|
||||
current->oidSum == UPN_OID) {
|
||||
/* found UPN oid, check name against user */
|
||||
int idx;
|
||||
|
||||
for (idx = 0; idx < current->len; idx++) {
|
||||
if (current->name[idx] == '@') break;
|
||||
/* UPN format is user @ domain, since currently
|
||||
* not doing any checks on domain it is not
|
||||
* treatied as an error if only the user name
|
||||
* is present without the domain */
|
||||
}
|
||||
|
||||
if ((int)XSTRLEN(usr) == idx &&
|
||||
XSTRNCMP(usr, current->name, idx) == 0) {
|
||||
usrMatch = 1;
|
||||
}
|
||||
}
|
||||
current = current->next;
|
||||
}
|
||||
|
||||
if (usrMatch == 0) {
|
||||
wolfSSH_Log(WS_LOG_ERROR, "[SSHD] incorrect user cert "
|
||||
"sent");
|
||||
ret = WOLFSSH_USERAUTH_INVALID_PUBLICKEY;
|
||||
}
|
||||
}
|
||||
FreeDecodedCert(dCert);
|
||||
#ifdef WOLFSSH_SMALL_STACK
|
||||
WFREE(dCert, NULL, DYNTYPE_CERT);
|
||||
#endif
|
||||
}
|
||||
FreeDecodedCert(&dCert);
|
||||
}
|
||||
#endif
|
||||
|
||||
|
|
|
|||
|
|
@ -483,7 +483,8 @@ static inline void ato32(const byte* c, word32* u32)
|
|||
#endif
|
||||
|
||||
|
||||
#ifdef WOLFSSH_CERTS
|
||||
#if defined(WOLFSSH_CERTS) && \
|
||||
(defined(OPENSSL_ALL) || defined(WOLFSSL_IP_ALT_NAME))
|
||||
static int ParseRFC6187(const byte* in, word32 inSz, byte** leafOut,
|
||||
word32* leafOutSz)
|
||||
{
|
||||
|
|
|
|||
Loading…
Reference in New Issue