Blame SOURCES/0004-Mass-replace-LASSO_SIGNATURE_METHOD_RSA_SHA1-with-la.patch

0719f5
From 0d34c97be1c761a9eb12692e4cc4eac58feb7d19 Mon Sep 17 00:00:00 2001
0719f5
From: Jakub Hrozek <jhrozek@redhat.com>
0719f5
Date: Tue, 15 Jun 2021 14:45:14 +0200
0719f5
Subject: [PATCH 4/7] Mass-replace LASSO_SIGNATURE_METHOD_RSA_SHA1 with
0719f5
 lasso_get_default_signature_method() (#54037)
0719f5
0719f5
This should be backwards-compatible but at the same time use the
0719f5
selected default instead of RSA-SHA1.
0719f5
0719f5
Related:
0719f5
https://dev.entrouvert.org/issues/54037
0719f5
---
0719f5
 lasso/id-ff/defederation.c            | 2 +-
0719f5
 lasso/id-ff/logout.c                  | 6 +++---
0719f5
 lasso/id-ff/name_identifier_mapping.c | 4 ++--
0719f5
 lasso/id-ff/name_registration.c       | 4 ++--
0719f5
 lasso/id-ff/provider.c                | 2 +-
0719f5
 lasso/xml/tools.c                     | 2 +-
0719f5
 tests/basic_tests.c                   | 6 +++---
0719f5
 7 files changed, 13 insertions(+), 13 deletions(-)
0719f5
0719f5
diff --git a/lasso/id-ff/defederation.c b/lasso/id-ff/defederation.c
0719f5
index d711e4eed..d2382f4ae 100644
0719f5
--- a/lasso/id-ff/defederation.c
0719f5
+++ b/lasso/id-ff/defederation.c
0719f5
@@ -251,7 +251,7 @@ lasso_defederation_init_notification(LassoDefederation *defederation, gchar *rem
0719f5
 				nameIdentifier,
0719f5
 				profile->server->certificate ?
0719f5
 					LASSO_SIGNATURE_TYPE_WITHX509 : LASSO_SIGNATURE_TYPE_SIMPLE,
0719f5
-				LASSO_SIGNATURE_METHOD_RSA_SHA1);
0719f5
+				lasso_get_default_signature_method());
0719f5
 		if (profile->msg_relayState) {
0719f5
 			message(G_LOG_LEVEL_WARNING,
0719f5
 					"RelayState was defined but can't be used "\
0719f5
diff --git a/lasso/id-ff/logout.c b/lasso/id-ff/logout.c
0719f5
index 20d04ed82..d307db586 100644
0719f5
--- a/lasso/id-ff/logout.c
0719f5
+++ b/lasso/id-ff/logout.c
0719f5
@@ -396,7 +396,7 @@ lasso_logout_build_response_msg(LassoLogout *logout)
0719f5
 						profile->server->certificate ?
0719f5
 						LASSO_SIGNATURE_TYPE_WITHX509 :
0719f5
 						LASSO_SIGNATURE_TYPE_SIMPLE,
0719f5
-						LASSO_SIGNATURE_METHOD_RSA_SHA1));
0719f5
+						lasso_get_default_signature_method()));
0719f5
 		} else if (profile->http_request_method == LASSO_HTTP_METHOD_REDIRECT) {
0719f5
 			lasso_assign_new_gobject(profile->response,
0719f5
 					lasso_lib_logout_response_new_full(
0719f5
@@ -608,7 +608,7 @@ lasso_logout_init_request(LassoLogout *logout, char *remote_providerID,
0719f5
 				nameIdentifier,
0719f5
 				profile->server->certificate ?
0719f5
 				LASSO_SIGNATURE_TYPE_WITHX509 : LASSO_SIGNATURE_TYPE_SIMPLE,
0719f5
-				LASSO_SIGNATURE_METHOD_RSA_SHA1);
0719f5
+				lasso_get_default_signature_method());
0719f5
 	} else { /* http_method == LASSO_HTTP_METHOD_REDIRECT */
0719f5
 		is_http_redirect_get_method = TRUE;
0719f5
 		lib_logout_request = (LassoLibLogoutRequest*)lasso_lib_logout_request_new_full(
0719f5
@@ -990,7 +990,7 @@ lasso_logout_validate_request(LassoLogout *logout)
0719f5
 				logout_request,
0719f5
 				profile->server->certificate ?
0719f5
 					LASSO_SIGNATURE_TYPE_WITHX509 : LASSO_SIGNATURE_TYPE_SIMPLE,
0719f5
-				LASSO_SIGNATURE_METHOD_RSA_SHA1));
0719f5
+				lasso_get_default_signature_method()));
0719f5
 	}
0719f5
 	if (profile->http_request_method == LASSO_HTTP_METHOD_REDIRECT) {
0719f5
 		lasso_assign_new_gobject(profile->response, lasso_lib_logout_response_new_full(
0719f5
diff --git a/lasso/id-ff/name_identifier_mapping.c b/lasso/id-ff/name_identifier_mapping.c
0719f5
index 80af6fec4..f84020eb6 100644
0719f5
--- a/lasso/id-ff/name_identifier_mapping.c
0719f5
+++ b/lasso/id-ff/name_identifier_mapping.c
0719f5
@@ -259,7 +259,7 @@ lasso_name_identifier_mapping_init_request(LassoNameIdentifierMapping *mapping,
0719f5
 			targetNamespace,
0719f5
 			profile->server->certificate ?
0719f5
 				LASSO_SIGNATURE_TYPE_WITHX509 : LASSO_SIGNATURE_TYPE_SIMPLE,
0719f5
-			LASSO_SIGNATURE_METHOD_RSA_SHA1);
0719f5
+			lasso_get_default_signature_method());
0719f5
 	if (LASSO_IS_LIB_NAME_IDENTIFIER_MAPPING_REQUEST(profile->request) == FALSE) {
0719f5
 		return critical_error(LASSO_PROFILE_ERROR_BUILDING_REQUEST_FAILED);
0719f5
 	}
0719f5
@@ -458,7 +458,7 @@ lasso_name_identifier_mapping_validate_request(LassoNameIdentifierMapping *mappi
0719f5
 			request,
0719f5
 			profile->server->certificate ?
0719f5
 				LASSO_SIGNATURE_TYPE_WITHX509 : LASSO_SIGNATURE_TYPE_SIMPLE,
0719f5
-			LASSO_SIGNATURE_METHOD_RSA_SHA1);
0719f5
+			lasso_get_default_signature_method());
0719f5
 
0719f5
 	if (LASSO_IS_LIB_NAME_IDENTIFIER_MAPPING_RESPONSE(profile->response) == FALSE) {
0719f5
 		return critical_error(LASSO_PROFILE_ERROR_BUILDING_RESPONSE_FAILED);
0719f5
diff --git a/lasso/id-ff/name_registration.c b/lasso/id-ff/name_registration.c
0719f5
index 11dbf24fe..076cf9624 100644
0719f5
--- a/lasso/id-ff/name_registration.c
0719f5
+++ b/lasso/id-ff/name_registration.c
0719f5
@@ -339,7 +339,7 @@ lasso_name_registration_init_request(LassoNameRegistration *name_registration,
0719f5
 			idpNameIdentifier, spNameIdentifier, oldNameIdentifier,
0719f5
 			profile->server->certificate ?
0719f5
 				LASSO_SIGNATURE_TYPE_WITHX509 : LASSO_SIGNATURE_TYPE_SIMPLE,
0719f5
-			LASSO_SIGNATURE_METHOD_RSA_SHA1);
0719f5
+			lasso_get_default_signature_method());
0719f5
 	if (profile->request == NULL) {
0719f5
 		return critical_error(LASSO_PROFILE_ERROR_BUILDING_REQUEST_FAILED);
0719f5
 	}
0719f5
@@ -575,7 +575,7 @@ lasso_name_registration_validate_request(LassoNameRegistration *name_registratio
0719f5
 			LASSO_LIB_REGISTER_NAME_IDENTIFIER_REQUEST(profile->request),
0719f5
 			profile->server->certificate ?
0719f5
 				LASSO_SIGNATURE_TYPE_WITHX509 : LASSO_SIGNATURE_TYPE_SIMPLE,
0719f5
-			LASSO_SIGNATURE_METHOD_RSA_SHA1);
0719f5
+			lasso_get_default_signature_method());
0719f5
 	if (LASSO_IS_LIB_REGISTER_NAME_IDENTIFIER_RESPONSE(profile->response) == FALSE) {
0719f5
 		return critical_error(LASSO_PROFILE_ERROR_BUILDING_RESPONSE_FAILED);
0719f5
 	}
0719f5
diff --git a/lasso/id-ff/provider.c b/lasso/id-ff/provider.c
0719f5
index 32a907d43..961c3669d 100644
0719f5
--- a/lasso/id-ff/provider.c
0719f5
+++ b/lasso/id-ff/provider.c
0719f5
@@ -1274,7 +1274,7 @@ lasso_provider_load_public_key(LassoProvider *provider, LassoPublicKeyType publi
0719f5
 
0719f5
 	if (public_key != NULL) {
0719f5
 		xmlSecKey *key = lasso_xmlsec_load_private_key(public_key, NULL,
0719f5
-				LASSO_SIGNATURE_METHOD_RSA_SHA1, NULL);
0719f5
+				lasso_get_default_signature_method(), NULL);
0719f5
 		if (key) {
0719f5
 			lasso_list_add_new_sec_key(keys, key);
0719f5
 		} else {
0719f5
diff --git a/lasso/xml/tools.c b/lasso/xml/tools.c
0719f5
index ce322ee1f..cf6dade09 100644
0719f5
--- a/lasso/xml/tools.c
0719f5
+++ b/lasso/xml/tools.c
0719f5
@@ -2746,7 +2746,7 @@ next:
0719f5
 		content = xmlNodeGetContent(key_value);
0719f5
 		if (content) {
0719f5
 			result = lasso_xmlsec_load_private_key_from_buffer((char*)content,
0719f5
-					strlen((char*)content), NULL, LASSO_SIGNATURE_METHOD_RSA_SHA1, NULL);
0719f5
+					strlen((char*)content), NULL, lasso_get_default_signature_method(), NULL);
0719f5
 			xmlFree(content);
0719f5
 		}
0719f5
 	}
0719f5
diff --git a/tests/basic_tests.c b/tests/basic_tests.c
0719f5
index f9cfef266..0652abc28 100644
0719f5
--- a/tests/basic_tests.c
0719f5
+++ b/tests/basic_tests.c
0719f5
@@ -2008,16 +2008,16 @@ START_TEST(test14_lasso_key)
0719f5
 
0719f5
 	check_true(g_file_get_contents(TESTSDATADIR "sp1-la/private-key-raw.pem", &buffer, &length, NULL));
0719f5
 	check_not_null(key = lasso_key_new_for_signature_from_memory(buffer,
0719f5
-				length, NULL, LASSO_SIGNATURE_METHOD_RSA_SHA1,
0719f5
+				length, NULL, lasso_get_default_signature_method(),
0719f5
 				NULL));
0719f5
 	lasso_release_gobject(key);
0719f5
 	check_not_null(key = lasso_key_new_for_signature_from_file(TESTSDATADIR
0719f5
-				"sp1-la/private-key-raw.pem", NULL, LASSO_SIGNATURE_METHOD_RSA_SHA1,
0719f5
+				"sp1-la/private-key-raw.pem", NULL, lasso_get_default_signature_method(),
0719f5
 				NULL));
0719f5
 	lasso_release_gobject(key);
0719f5
 	base64_encoded = g_base64_encode(BAD_CAST buffer, length);
0719f5
 	check_not_null(key = lasso_key_new_for_signature_from_base64_string(base64_encoded, NULL,
0719f5
-				LASSO_SIGNATURE_METHOD_RSA_SHA1, NULL));
0719f5
+				lasso_get_default_signature_method(), NULL));
0719f5
 	lasso_release_string(base64_encoded);
0719f5
 	lasso_release_string(buffer);
0719f5
 	lasso_release_gobject(key);
0719f5
-- 
0719f5
2.26.3
0719f5