Commit 9583b61
authored
Ensure correct certificate is used for TSA auth checks (GHSA-xm5m-wgh2-rrg3) (#1333)
Currently VerifyLeafCert and verifyTSRWithChain may disagree
on which cert is the real leaf certificate (TSA certificate):
VerifyLeafCert should use the leaf certificate identified by
verifyTSRWithChain.
* Return the signer cert from verifyTSRWithChain() so
verifyLeafCert() can just use the correct cert
* Make sure verifyTSRWithChain() ensures that we have signer cert
(either embedded or provided as option)
* Make sure verifyTSRWithChain() verifies that embedded and
provided cert match if both are present
* Modify verifyLeafCert() so it only operates on given leaf cert
* Remove unused function
verifyEmbeddedLeafCert is now not needed: the check is already
done in verifyTSRWithChain.
Remove the related test, add test cases to cover the same
situatation in verifyTSRWithChain.
Signed-off-by: Jussi Kukkonen <[email protected]>1 parent 7aab8b4 commit 9583b61
3 files changed
Lines changed: 106 additions & 96 deletions
Binary file not shown.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
81 | 81 | | |
82 | 82 | | |
83 | 83 | | |
84 | | - | |
85 | | - | |
86 | | - | |
87 | | - | |
88 | | - | |
89 | | - | |
90 | | - | |
91 | | - | |
92 | 84 | | |
93 | 85 | | |
94 | 86 | | |
| |||
104 | 96 | | |
105 | 97 | | |
106 | 98 | | |
107 | | - | |
108 | | - | |
109 | | - | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
110 | 103 | | |
111 | 104 | | |
112 | 105 | | |
113 | 106 | | |
114 | | - | |
115 | | - | |
116 | | - | |
117 | | - | |
118 | | - | |
119 | | - | |
120 | | - | |
121 | | - | |
122 | | - | |
123 | | - | |
124 | | - | |
125 | | - | |
126 | | - | |
127 | | - | |
128 | | - | |
129 | | - | |
130 | | - | |
131 | | - | |
132 | | - | |
133 | | - | |
134 | 107 | | |
135 | 108 | | |
136 | 109 | | |
| |||
252 | 225 | | |
253 | 226 | | |
254 | 227 | | |
255 | | - | |
| 228 | + | |
| 229 | + | |
256 | 230 | | |
257 | 231 | | |
258 | 232 | | |
| |||
264 | 238 | | |
265 | 239 | | |
266 | 240 | | |
267 | | - | |
| 241 | + | |
268 | 242 | | |
269 | 243 | | |
270 | 244 | | |
| |||
277 | 251 | | |
278 | 252 | | |
279 | 253 | | |
280 | | - | |
| 254 | + | |
| 255 | + | |
281 | 256 | | |
282 | 257 | | |
283 | | - | |
| 258 | + | |
284 | 259 | | |
285 | 260 | | |
286 | 261 | | |
287 | | - | |
| 262 | + | |
288 | 263 | | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
289 | 269 | | |
290 | 270 | | |
291 | 271 | | |
292 | 272 | | |
293 | 273 | | |
294 | 274 | | |
295 | 275 | | |
296 | | - | |
| 276 | + | |
297 | 277 | | |
298 | 278 | | |
299 | 279 | | |
| |||
313 | 293 | | |
314 | 294 | | |
315 | 295 | | |
316 | | - | |
| 296 | + | |
317 | 297 | | |
318 | 298 | | |
319 | 299 | | |
320 | 300 | | |
321 | 301 | | |
322 | | - | |
| 302 | + | |
323 | 303 | | |
324 | 304 | | |
325 | | - | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
| 313 | + | |
| 314 | + | |
326 | 315 | | |
327 | 316 | | |
328 | 317 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
| 30 | + | |
30 | 31 | | |
31 | 32 | | |
32 | 33 | | |
| |||
107 | 108 | | |
108 | 109 | | |
109 | 110 | | |
110 | | - | |
111 | | - | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
112 | 114 | | |
113 | 115 | | |
114 | 116 | | |
| |||
192 | 194 | | |
193 | 195 | | |
194 | 196 | | |
195 | | - | |
| 197 | + | |
196 | 198 | | |
197 | 199 | | |
198 | 200 | | |
| |||
213 | 215 | | |
214 | 216 | | |
215 | 217 | | |
216 | | - | |
| 218 | + | |
217 | 219 | | |
218 | 220 | | |
219 | 221 | | |
| |||
246 | 248 | | |
247 | 249 | | |
248 | 250 | | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
249 | 256 | | |
250 | 257 | | |
251 | 258 | | |
252 | 259 | | |
253 | 260 | | |
254 | | - | |
| 261 | + | |
255 | 262 | | |
256 | 263 | | |
257 | 264 | | |
| |||
267 | 274 | | |
268 | 275 | | |
269 | 276 | | |
270 | | - | |
271 | | - | |
272 | | - | |
273 | | - | |
274 | | - | |
275 | | - | |
276 | | - | |
277 | | - | |
278 | | - | |
279 | | - | |
280 | | - | |
281 | | - | |
282 | | - | |
283 | | - | |
284 | | - | |
285 | | - | |
286 | | - | |
287 | | - | |
288 | | - | |
289 | | - | |
290 | | - | |
291 | | - | |
292 | | - | |
293 | | - | |
294 | | - | |
295 | | - | |
296 | | - | |
297 | | - | |
298 | | - | |
299 | | - | |
300 | | - | |
301 | | - | |
302 | | - | |
303 | | - | |
304 | | - | |
305 | | - | |
306 | | - | |
307 | | - | |
308 | | - | |
309 | | - | |
310 | | - | |
311 | | - | |
312 | | - | |
313 | | - | |
314 | | - | |
315 | | - | |
316 | | - | |
317 | | - | |
318 | | - | |
319 | | - | |
320 | 277 | | |
321 | 278 | | |
322 | 279 | | |
| |||
591 | 548 | | |
592 | 549 | | |
593 | 550 | | |
| 551 | + | |
| 552 | + | |
| 553 | + | |
| 554 | + | |
| 555 | + | |
594 | 556 | | |
595 | 557 | | |
596 | 558 | | |
| |||
603 | 565 | | |
604 | 566 | | |
605 | 567 | | |
| 568 | + | |
606 | 569 | | |
607 | 570 | | |
608 | 571 | | |
| |||
654 | 617 | | |
655 | 618 | | |
656 | 619 | | |
| 620 | + | |
| 621 | + | |
| 622 | + | |
| 623 | + | |
| 624 | + | |
| 625 | + | |
| 626 | + | |
| 627 | + | |
| 628 | + | |
| 629 | + | |
| 630 | + | |
| 631 | + | |
| 632 | + | |
| 633 | + | |
| 634 | + | |
| 635 | + | |
| 636 | + | |
| 637 | + | |
| 638 | + | |
| 639 | + | |
657 | 640 | | |
658 | 641 | | |
659 | 642 | | |
| |||
691 | 674 | | |
692 | 675 | | |
693 | 676 | | |
694 | | - | |
| 677 | + | |
695 | 678 | | |
696 | 679 | | |
697 | 680 | | |
| |||
700 | 683 | | |
701 | 684 | | |
702 | 685 | | |
| 686 | + | |
| 687 | + | |
| 688 | + | |
| 689 | + | |
| 690 | + | |
| 691 | + | |
| 692 | + | |
| 693 | + | |
| 694 | + | |
| 695 | + | |
| 696 | + | |
| 697 | + | |
| 698 | + | |
| 699 | + | |
| 700 | + | |
| 701 | + | |
| 702 | + | |
| 703 | + | |
| 704 | + | |
| 705 | + | |
| 706 | + | |
| 707 | + | |
| 708 | + | |
| 709 | + | |
| 710 | + | |
| 711 | + | |
| 712 | + | |
| 713 | + | |
| 714 | + | |
| 715 | + | |
| 716 | + | |
| 717 | + | |
| 718 | + | |
| 719 | + | |
| 720 | + | |
| 721 | + | |
| 722 | + | |
| 723 | + | |
0 commit comments