|
|
3af7f6 |
From c8050d1e6eb0f4f3deb187224945ddcfc3baa4d6 Mon Sep 17 00:00:00 2001
|
|
|
3af7f6 |
From: Howard Chu <hyc@openldap.org>
|
|
|
3af7f6 |
Date: Fri, 21 Aug 2020 09:15:15 +0100
|
|
|
3af7f6 |
Subject: [PATCH] ITS#9318 add TLS_REQSAN option
|
|
|
3af7f6 |
|
|
|
3af7f6 |
Add an option to specify how subjectAlternativeNames should be
|
|
|
3af7f6 |
handled when validating the names in a server certificate.
|
|
|
3af7f6 |
---
|
|
|
3af7f6 |
doc/man/man3/ldap_get_option.3 | 9 +++++++
|
|
|
3af7f6 |
doc/man/man5/ldap.conf.5 | 31 +++++++++++++++++++++++
|
|
|
3af7f6 |
include/ldap.h | 1 +
|
|
|
3af7f6 |
libraries/libldap/init.c | 2 ++
|
|
|
3af7f6 |
libraries/libldap/ldap-int.h | 1 +
|
|
|
3af7f6 |
libraries/libldap/tls2.c | 16 ++++++++++++
|
|
|
3af7f6 |
libraries/libldap/tls_g.c | 46 ++++++++++++++++++++++++++++++++--
|
|
|
3af7f6 |
libraries/libldap/tls_o.c | 44 ++++++++++++++++++++++++++++++--
|
|
|
3af7f6 |
8 files changed, 146 insertions(+), 4 deletions(-)
|
|
|
3af7f6 |
|
|
|
3af7f6 |
diff --git a/doc/man/man3/ldap_get_option.3 b/doc/man/man3/ldap_get_option.3
|
|
|
3af7f6 |
index d229ce6e3..7d760136f 100644
|
|
|
3af7f6 |
--- a/doc/man/man3/ldap_get_option.3
|
|
|
3af7f6 |
+++ b/doc/man/man3/ldap_get_option.3
|
|
|
3af7f6 |
@@ -788,6 +788,15 @@ one of
|
|
|
3af7f6 |
.BR LDAP_OPT_X_TLS_ALLOW ,
|
|
|
3af7f6 |
.BR LDAP_OPT_X_TLS_TRY .
|
|
|
3af7f6 |
.TP
|
|
|
3af7f6 |
+.B LDAP_OPT_X_TLS_REQUIRE_SAN
|
|
|
3af7f6 |
+Sets/gets the peer certificate subjectAlternativeName checking strategy,
|
|
|
3af7f6 |
+one of
|
|
|
3af7f6 |
+.BR LDAP_OPT_X_TLS_NEVER ,
|
|
|
3af7f6 |
+.BR LDAP_OPT_X_TLS_HARD ,
|
|
|
3af7f6 |
+.BR LDAP_OPT_X_TLS_DEMAND ,
|
|
|
3af7f6 |
+.BR LDAP_OPT_X_TLS_ALLOW ,
|
|
|
3af7f6 |
+.BR LDAP_OPT_X_TLS_TRY .
|
|
|
3af7f6 |
+.TP
|
|
|
3af7f6 |
.B LDAP_OPT_X_TLS_SSL_CTX
|
|
|
3af7f6 |
Gets the TLS session context associated with this handle.
|
|
|
3af7f6 |
.BR outvalue
|
|
|
3af7f6 |
diff --git a/doc/man/man5/ldap.conf.5 b/doc/man/man5/ldap.conf.5
|
|
|
3af7f6 |
index 2f1ee886d..cde2c875f 100644
|
|
|
3af7f6 |
--- a/doc/man/man5/ldap.conf.5
|
|
|
3af7f6 |
+++ b/doc/man/man5/ldap.conf.5
|
|
|
3af7f6 |
@@ -464,6 +464,37 @@ certificate is provided, or a bad certificate is provided, the session
|
|
|
3af7f6 |
is immediately terminated. This is the default setting.
|
|
|
3af7f6 |
.RE
|
|
|
3af7f6 |
.TP
|
|
|
3af7f6 |
+.B TLS_REQSAN <level>
|
|
|
3af7f6 |
+Specifies what checks to perform on the subjectAlternativeName
|
|
|
3af7f6 |
+(SAN) extensions in a server certificate when validating the certificate
|
|
|
3af7f6 |
+name against the specified hostname of the server. The
|
|
|
3af7f6 |
+.B <level>
|
|
|
3af7f6 |
+can be specified as one of the following keywords:
|
|
|
3af7f6 |
+.RS
|
|
|
3af7f6 |
+.TP
|
|
|
3af7f6 |
+.B never
|
|
|
3af7f6 |
+The client will not check any SAN in the certificate.
|
|
|
3af7f6 |
+.TP
|
|
|
3af7f6 |
+.B allow
|
|
|
3af7f6 |
+The SAN is checked against the specified hostname. If a SAN is
|
|
|
3af7f6 |
+present but none match the specified hostname, the SANs are ignored
|
|
|
3af7f6 |
+and the usual check against the certificate DN is used.
|
|
|
3af7f6 |
+This is the default setting.
|
|
|
3af7f6 |
+.TP
|
|
|
3af7f6 |
+.B try
|
|
|
3af7f6 |
+The SAN is checked against the specified hostname. If no SAN is present
|
|
|
3af7f6 |
+in the server certificate, the usual check against the certificate DN
|
|
|
3af7f6 |
+is used. If a SAN is present but doesn't match the specified hostname,
|
|
|
3af7f6 |
+the session is immediately terminated. This setting may be preferred
|
|
|
3af7f6 |
+when a mix of certs with and without SANs are in use.
|
|
|
3af7f6 |
+.TP
|
|
|
3af7f6 |
+.B demand | hard
|
|
|
3af7f6 |
+These keywords are equivalent. The SAN is checked against the specified
|
|
|
3af7f6 |
+hostname. If no SAN is present in the server certificate, or no SANs
|
|
|
3af7f6 |
+match, the session is immediately terminated. This setting should be
|
|
|
3af7f6 |
+used when only certificates with SANs are in use.
|
|
|
3af7f6 |
+.RE
|
|
|
3af7f6 |
+.TP
|
|
|
3af7f6 |
.B TLS_CRLCHECK <level>
|
|
|
3af7f6 |
Specifies if the Certificate Revocation List (CRL) of the CA should be
|
|
|
3af7f6 |
used to verify if the server certificates have not been revoked. This
|
|
|
3af7f6 |
diff --git a/include/ldap.h b/include/ldap.h
|
|
|
3af7f6 |
index 4b81a6841..4877de24a 100644
|
|
|
3af7f6 |
--- a/include/ldap.h
|
|
|
3af7f6 |
+++ b/include/ldap.h
|
|
|
3af7f6 |
@@ -160,6 +160,7 @@ LDAP_BEGIN_DECL
|
|
|
3af7f6 |
#define LDAP_OPT_X_TLS_PACKAGE 0x6011
|
|
|
3af7f6 |
#define LDAP_OPT_X_TLS_ECNAME 0x6012
|
|
|
3af7f6 |
#define LDAP_OPT_X_TLS_PEERCERT 0x6015 /* read-only */
|
|
|
3af7f6 |
+#define LDAP_OPT_X_TLS_REQUIRE_SAN 0x601a
|
|
|
3af7f6 |
|
|
|
3af7f6 |
#define LDAP_OPT_X_TLS_NEVER 0
|
|
|
3af7f6 |
#define LDAP_OPT_X_TLS_HARD 1
|
|
|
3af7f6 |
diff --git a/libraries/libldap/init.c b/libraries/libldap/init.c
|
|
|
3af7f6 |
index d503019aa..0d91808ec 100644
|
|
|
3af7f6 |
--- a/libraries/libldap/init.c
|
|
|
3af7f6 |
+++ b/libraries/libldap/init.c
|
|
|
3af7f6 |
@@ -128,6 +128,7 @@ static const struct ol_attribute {
|
|
|
3af7f6 |
{0, ATTR_TLS, "TLS_CACERT", NULL, LDAP_OPT_X_TLS_CACERTFILE},
|
|
|
3af7f6 |
{0, ATTR_TLS, "TLS_CACERTDIR", NULL, LDAP_OPT_X_TLS_CACERTDIR},
|
|
|
3af7f6 |
{0, ATTR_TLS, "TLS_REQCERT", NULL, LDAP_OPT_X_TLS_REQUIRE_CERT},
|
|
|
3af7f6 |
+ {0, ATTR_TLS, "TLS_REQSAN", NULL, LDAP_OPT_X_TLS_REQUIRE_SAN},
|
|
|
3af7f6 |
{0, ATTR_TLS, "TLS_RANDFILE", NULL, LDAP_OPT_X_TLS_RANDOM_FILE},
|
|
|
3af7f6 |
{0, ATTR_TLS, "TLS_CIPHER_SUITE", NULL, LDAP_OPT_X_TLS_CIPHER_SUITE},
|
|
|
3af7f6 |
{0, ATTR_TLS, "TLS_PROTOCOL_MIN", NULL, LDAP_OPT_X_TLS_PROTOCOL_MIN},
|
|
|
3af7f6 |
@@ -624,6 +625,7 @@ void ldap_int_initialize_global_options( struct ldapoptions *gopts, int *dbglvl
|
|
|
3af7f6 |
gopts->ldo_tls_connect_cb = NULL;
|
|
|
3af7f6 |
gopts->ldo_tls_connect_arg = NULL;
|
|
|
3af7f6 |
gopts->ldo_tls_require_cert = LDAP_OPT_X_TLS_DEMAND;
|
|
|
3af7f6 |
+ gopts->ldo_tls_require_san = LDAP_OPT_X_TLS_ALLOW;
|
|
|
3af7f6 |
#endif
|
|
|
3af7f6 |
gopts->ldo_keepalive_probes = 0;
|
|
|
3af7f6 |
gopts->ldo_keepalive_interval = 0;
|
|
|
3af7f6 |
diff --git a/libraries/libldap/ldap-int.h b/libraries/libldap/ldap-int.h
|
|
|
3af7f6 |
index 753014ad0..2bf5d4ff6 100644
|
|
|
3af7f6 |
--- a/libraries/libldap/ldap-int.h
|
|
|
3af7f6 |
+++ b/libraries/libldap/ldap-int.h
|
|
|
3af7f6 |
@@ -262,6 +262,7 @@ struct ldapoptions {
|
|
|
3af7f6 |
int ldo_tls_require_cert;
|
|
|
3af7f6 |
int ldo_tls_impl;
|
|
|
3af7f6 |
int ldo_tls_crlcheck;
|
|
|
3af7f6 |
+ int ldo_tls_require_san;
|
|
|
3af7f6 |
#define LDAP_LDO_TLS_NULLARG ,0,0,0,{0,0,0,0,0,0,0,0,0},0,0,0,0
|
|
|
3af7f6 |
#else
|
|
|
3af7f6 |
#define LDAP_LDO_TLS_NULLARG
|
|
|
3af7f6 |
diff --git a/libraries/libldap/tls2.c b/libraries/libldap/tls2.c
|
|
|
3af7f6 |
index 6a2113255..670292c22 100644
|
|
|
3af7f6 |
--- a/libraries/libldap/tls2.c
|
|
|
3af7f6 |
+++ b/libraries/libldap/tls2.c
|
|
|
3af7f6 |
@@ -539,6 +539,7 @@ ldap_int_tls_config( LDAP *ld, int option, const char *arg )
|
|
|
3af7f6 |
return ldap_pvt_tls_set_option( ld, option, (void *) arg );
|
|
|
3af7f6 |
|
|
|
3af7f6 |
case LDAP_OPT_X_TLS_REQUIRE_CERT:
|
|
|
3af7f6 |
+ case LDAP_OPT_X_TLS_REQUIRE_SAN:
|
|
|
3af7f6 |
case LDAP_OPT_X_TLS:
|
|
|
3af7f6 |
i = -1;
|
|
|
3af7f6 |
if ( strcasecmp( arg, "never" ) == 0 ) {
|
|
|
3af7f6 |
@@ -669,6 +670,9 @@ ldap_pvt_tls_get_option( LDAP *ld, int option, void *arg )
|
|
|
3af7f6 |
case LDAP_OPT_X_TLS_REQUIRE_CERT:
|
|
|
3af7f6 |
*(int *)arg = lo->ldo_tls_require_cert;
|
|
|
3af7f6 |
break;
|
|
|
3af7f6 |
+ case LDAP_OPT_X_TLS_REQUIRE_SAN:
|
|
|
3af7f6 |
+ *(int *)arg = lo->ldo_tls_require_san;
|
|
|
3af7f6 |
+ break;
|
|
|
3af7f6 |
#ifdef HAVE_OPENSSL_CRL
|
|
|
3af7f6 |
case LDAP_OPT_X_TLS_CRLCHECK: /* OpenSSL only */
|
|
|
3af7f6 |
*(int *)arg = lo->ldo_tls_crlcheck;
|
|
|
3af7f6 |
@@ -818,6 +822,18 @@ ldap_pvt_tls_set_option( LDAP *ld, int option, void *arg )
|
|
|
3af7f6 |
return 0;
|
|
|
3af7f6 |
}
|
|
|
3af7f6 |
return -1;
|
|
|
3af7f6 |
+ case LDAP_OPT_X_TLS_REQUIRE_SAN:
|
|
|
3af7f6 |
+ if ( !arg ) return -1;
|
|
|
3af7f6 |
+ switch( *(int *) arg ) {
|
|
|
3af7f6 |
+ case LDAP_OPT_X_TLS_NEVER:
|
|
|
3af7f6 |
+ case LDAP_OPT_X_TLS_DEMAND:
|
|
|
3af7f6 |
+ case LDAP_OPT_X_TLS_ALLOW:
|
|
|
3af7f6 |
+ case LDAP_OPT_X_TLS_TRY:
|
|
|
3af7f6 |
+ case LDAP_OPT_X_TLS_HARD:
|
|
|
3af7f6 |
+ lo->ldo_tls_require_san = * (int *) arg;
|
|
|
3af7f6 |
+ return 0;
|
|
|
3af7f6 |
+ }
|
|
|
3af7f6 |
+ return -1;
|
|
|
3af7f6 |
#ifdef HAVE_OPENSSL_CRL
|
|
|
3af7f6 |
case LDAP_OPT_X_TLS_CRLCHECK: /* OpenSSL only */
|
|
|
3af7f6 |
if ( !arg ) return -1;
|
|
|
3af7f6 |
diff --git a/libraries/libldap/tls_g.c b/libraries/libldap/tls_g.c
|
|
|
3af7f6 |
index 15ce0bbb8..e3486c9b4 100644
|
|
|
3af7f6 |
--- a/libraries/libldap/tls_g.c
|
|
|
3af7f6 |
+++ b/libraries/libldap/tls_g.c
|
|
|
3af7f6 |
@@ -496,6 +496,7 @@ tlsg_session_chkhost( LDAP *ld, tls_session *session, const char *name_in )
|
|
|
3af7f6 |
{
|
|
|
3af7f6 |
tlsg_session *s = (tlsg_session *)session;
|
|
|
3af7f6 |
int i, ret;
|
|
|
3af7f6 |
+ int chkSAN = ld->ld_options.ldo_tls_require_san, gotSAN = 0;
|
|
|
3af7f6 |
const gnutls_datum_t *peer_cert_list;
|
|
|
3af7f6 |
unsigned int list_size;
|
|
|
3af7f6 |
char altname[NI_MAXHOST];
|
|
|
3af7f6 |
@@ -558,12 +559,14 @@ tlsg_session_chkhost( LDAP *ld, tls_session *session, const char *name_in )
|
|
|
3af7f6 |
}
|
|
|
3af7f6 |
}
|
|
|
3af7f6 |
|
|
|
3af7f6 |
+ if (chkSAN) {
|
|
|
3af7f6 |
for ( i=0, ret=0; ret >= 0; i++ ) {
|
|
|
3af7f6 |
altnamesize = sizeof(altname);
|
|
|
3af7f6 |
ret = gnutls_x509_crt_get_subject_alt_name( cert, i,
|
|
|
3af7f6 |
altname, &altnamesize, NULL );
|
|
|
3af7f6 |
if ( ret < 0 ) break;
|
|
|
3af7f6 |
|
|
|
3af7f6 |
+ gotSAN = 1;
|
|
|
3af7f6 |
/* ignore empty */
|
|
|
3af7f6 |
if ( altnamesize == 0 ) continue;
|
|
|
3af7f6 |
|
|
|
3af7f6 |
@@ -599,7 +602,45 @@ tlsg_session_chkhost( LDAP *ld, tls_session *session, const char *name_in )
|
|
|
3af7f6 |
}
|
|
|
3af7f6 |
if ( ret >= 0 ) {
|
|
|
3af7f6 |
ret = LDAP_SUCCESS;
|
|
|
3af7f6 |
- } else {
|
|
|
3af7f6 |
+ }
|
|
|
3af7f6 |
+ }
|
|
|
3af7f6 |
+ if (ret != LDAP_SUCCESS && chkSAN) {
|
|
|
3af7f6 |
+ switch(chkSAN) {
|
|
|
3af7f6 |
+ case LDAP_OPT_X_TLS_DEMAND:
|
|
|
3af7f6 |
+ case LDAP_OPT_X_TLS_HARD:
|
|
|
3af7f6 |
+ if (!gotSAN) {
|
|
|
3af7f6 |
+ Debug( LDAP_DEBUG_ANY,
|
|
|
3af7f6 |
+ "TLS: unable to get subjectAltName from peer certificate.\n",
|
|
|
3af7f6 |
+ 0, 0, 0 );
|
|
|
3af7f6 |
+ ret = LDAP_CONNECT_ERROR;
|
|
|
3af7f6 |
+ if ( ld->ld_error ) {
|
|
|
3af7f6 |
+ LDAP_FREE( ld->ld_error );
|
|
|
3af7f6 |
+ }
|
|
|
3af7f6 |
+ ld->ld_error = LDAP_STRDUP(
|
|
|
3af7f6 |
+ _("TLS: unable to get subjectAltName from peer certificate"));
|
|
|
3af7f6 |
+ goto done;
|
|
|
3af7f6 |
+ }
|
|
|
3af7f6 |
+ /* FALLTHRU */
|
|
|
3af7f6 |
+ case LDAP_OPT_X_TLS_TRY:
|
|
|
3af7f6 |
+ if (gotSAN) {
|
|
|
3af7f6 |
+ Debug( LDAP_DEBUG_ANY, "TLS: hostname (%s) does not match "
|
|
|
3af7f6 |
+ "subjectAltName in certificate.\n",
|
|
|
3af7f6 |
+ name, 0, 0 );
|
|
|
3af7f6 |
+ ret = LDAP_CONNECT_ERROR;
|
|
|
3af7f6 |
+ if ( ld->ld_error ) {
|
|
|
3af7f6 |
+ LDAP_FREE( ld->ld_error );
|
|
|
3af7f6 |
+ }
|
|
|
3af7f6 |
+ ld->ld_error = LDAP_STRDUP(
|
|
|
3af7f6 |
+ _("TLS: hostname does not match subjectAltName in peer certificate"));
|
|
|
3af7f6 |
+ goto done;
|
|
|
3af7f6 |
+ }
|
|
|
3af7f6 |
+ break;
|
|
|
3af7f6 |
+ case LDAP_OPT_X_TLS_ALLOW:
|
|
|
3af7f6 |
+ break;
|
|
|
3af7f6 |
+ }
|
|
|
3af7f6 |
+ }
|
|
|
3af7f6 |
+
|
|
|
3af7f6 |
+ if ( ret != LDAP_SUCCESS ){
|
|
|
3af7f6 |
/* find the last CN */
|
|
|
3af7f6 |
i=0;
|
|
|
3af7f6 |
do {
|
|
|
3af7f6 |
@@ -654,9 +695,10 @@ tlsg_session_chkhost( LDAP *ld, tls_session *session, const char *name_in )
|
|
|
3af7f6 |
LDAP_FREE( ld->ld_error );
|
|
|
3af7f6 |
}
|
|
|
3af7f6 |
ld->ld_error = LDAP_STRDUP(
|
|
|
3af7f6 |
- _("TLS: hostname does not match CN in peer certificate"));
|
|
|
3af7f6 |
+ _("TLS: hostname does not match name in peer certificate"));
|
|
|
3af7f6 |
}
|
|
|
3af7f6 |
}
|
|
|
3af7f6 |
+done:
|
|
|
3af7f6 |
gnutls_x509_crt_deinit( cert );
|
|
|
3af7f6 |
return ret;
|
|
|
3af7f6 |
}
|
|
|
3af7f6 |
diff --git a/libraries/libldap/tls_o.c b/libraries/libldap/tls_o.c
|
|
|
3af7f6 |
index 4006f7a4f..6f27168e9 100644
|
|
|
3af7f6 |
--- a/libraries/libldap/tls_o.c
|
|
|
3af7f6 |
+++ b/libraries/libldap/tls_o.c
|
|
|
3af7f6 |
@@ -600,6 +600,7 @@ tlso_session_chkhost( LDAP *ld, tls_session *sess, const char *name_in )
|
|
|
3af7f6 |
{
|
|
|
3af7f6 |
tlso_session *s = (tlso_session *)sess;
|
|
|
3af7f6 |
int i, ret = LDAP_LOCAL_ERROR;
|
|
|
3af7f6 |
+ int chkSAN = ld->ld_options.ldo_tls_require_san, gotSAN = 0;
|
|
|
3af7f6 |
X509 *x;
|
|
|
3af7f6 |
const char *name;
|
|
|
3af7f6 |
char *ptr;
|
|
|
3af7f6 |
@@ -638,7 +639,8 @@ tlso_session_chkhost( LDAP *ld, tls_session *sess, const char *name_in )
|
|
|
3af7f6 |
if ((ptr = strrchr(name, '.')) && isdigit((unsigned char)ptr[1])) {
|
|
|
3af7f6 |
if (inet_aton(name, (struct in_addr *)&addr)) ntype = IS_IP4;
|
|
|
3af7f6 |
}
|
|
|
3af7f6 |
-
|
|
|
3af7f6 |
+
|
|
|
3af7f6 |
+ if (chkSAN) {
|
|
|
3af7f6 |
i = X509_get_ext_by_NID(x, NID_subject_alt_name, -1);
|
|
|
3af7f6 |
if (i >= 0) {
|
|
|
3af7f6 |
X509_EXTENSION *ex;
|
|
|
3af7f6 |
@@ -651,6 +653,7 @@ tlso_session_chkhost( LDAP *ld, tls_session *sess, const char *name_in )
|
|
|
3af7f6 |
char *domain = NULL;
|
|
|
3af7f6 |
GENERAL_NAME *gn;
|
|
|
3af7f6 |
|
|
|
3af7f6 |
+ gotSAN = 1;
|
|
|
3af7f6 |
if (ntype == IS_DNS) {
|
|
|
3af7f6 |
domain = strchr(name, '.');
|
|
|
3af7f6 |
if (domain) {
|
|
|
3af7f6 |
@@ -709,6 +712,42 @@ tlso_session_chkhost( LDAP *ld, tls_session *sess, const char *name_in )
|
|
|
3af7f6 |
}
|
|
|
3af7f6 |
}
|
|
|
3af7f6 |
}
|
|
|
3af7f6 |
+ }
|
|
|
3af7f6 |
+ if (ret != LDAP_SUCCESS && chkSAN) {
|
|
|
3af7f6 |
+ switch(chkSAN) {
|
|
|
3af7f6 |
+ case LDAP_OPT_X_TLS_DEMAND:
|
|
|
3af7f6 |
+ case LDAP_OPT_X_TLS_HARD:
|
|
|
3af7f6 |
+ if (!gotSAN) {
|
|
|
3af7f6 |
+ Debug( LDAP_DEBUG_ANY,
|
|
|
3af7f6 |
+ "TLS: unable to get subjectAltName from peer certificate.\n",
|
|
|
3af7f6 |
+ 0, 0, 0 );
|
|
|
3af7f6 |
+ ret = LDAP_CONNECT_ERROR;
|
|
|
3af7f6 |
+ if ( ld->ld_error ) {
|
|
|
3af7f6 |
+ LDAP_FREE( ld->ld_error );
|
|
|
3af7f6 |
+ }
|
|
|
3af7f6 |
+ ld->ld_error = LDAP_STRDUP(
|
|
|
3af7f6 |
+ _("TLS: unable to get subjectAltName from peer certificate"));
|
|
|
3af7f6 |
+ goto done;
|
|
|
3af7f6 |
+ }
|
|
|
3af7f6 |
+ /* FALLTHRU */
|
|
|
3af7f6 |
+ case LDAP_OPT_X_TLS_TRY:
|
|
|
3af7f6 |
+ if (gotSAN) {
|
|
|
3af7f6 |
+ Debug( LDAP_DEBUG_ANY, "TLS: hostname (%s) does not match "
|
|
|
3af7f6 |
+ "subjectAltName in certificate.\n",
|
|
|
3af7f6 |
+ name, 0, 0 );
|
|
|
3af7f6 |
+ ret = LDAP_CONNECT_ERROR;
|
|
|
3af7f6 |
+ if ( ld->ld_error ) {
|
|
|
3af7f6 |
+ LDAP_FREE( ld->ld_error );
|
|
|
3af7f6 |
+ }
|
|
|
3af7f6 |
+ ld->ld_error = LDAP_STRDUP(
|
|
|
3af7f6 |
+ _("TLS: hostname does not match subjectAltName in peer certificate"));
|
|
|
3af7f6 |
+ goto done;
|
|
|
3af7f6 |
+ }
|
|
|
3af7f6 |
+ break;
|
|
|
3af7f6 |
+ case LDAP_OPT_X_TLS_ALLOW:
|
|
|
3af7f6 |
+ break;
|
|
|
3af7f6 |
+ }
|
|
|
3af7f6 |
+ }
|
|
|
3af7f6 |
|
|
|
3af7f6 |
if (ret != LDAP_SUCCESS) {
|
|
|
3af7f6 |
X509_NAME *xn;
|
|
|
3af7f6 |
@@ -772,9 +811,10 @@ no_cn:
|
|
|
3af7f6 |
LDAP_FREE( ld->ld_error );
|
|
|
3af7f6 |
}
|
|
|
3af7f6 |
ld->ld_error = LDAP_STRDUP(
|
|
|
3af7f6 |
- _("TLS: hostname does not match CN in peer certificate"));
|
|
|
3af7f6 |
+ _("TLS: hostname does not match name in peer certificate"));
|
|
|
3af7f6 |
}
|
|
|
3af7f6 |
}
|
|
|
3af7f6 |
+done:
|
|
|
3af7f6 |
X509_free(x);
|
|
|
3af7f6 |
return ret;
|
|
|
3af7f6 |
}
|
|
|
3af7f6 |
--
|
|
|
3af7f6 |
2.31.1
|
|
|
3af7f6 |
|