Skip to content
Open

2.4.x #817

Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions modules/ssl/ssl_engine_ocsp.c
Original file line number Diff line number Diff line change
Expand Up @@ -38,8 +38,8 @@ static const char *extract_responder_uri(X509 *cert, apr_pool_t *pool)
/* Name found in extension, and is a URI: */
if (OBJ_obj2nid(value->method) == NID_ad_OCSP
&& value->location->type == GEN_URI) {
const ASN1_STRING *uri = value->location->d.uniformResourceIdentifier;
result = modssl_ASN1_STRING_convert(pool, uri, 0);
result = apr_pstrdup(pool,
(char *)ASN1_STRING_get0_data(value->location->d.uniformResourceIdentifier));
}
}

Expand Down Expand Up @@ -140,7 +140,7 @@ static int verify_ocsp_status(X509 *cert, X509_STORE_CTX *ctx, conn_rec *c,
ruri = determine_responder_uri(sc, cert, c, pool);
if (!ruri) {
if (sc->server->ocsp_mask & SSL_OCSPCHECK_NO_OCSP_FOR_CERT_OK) {
ap_log_cerror(APLOG_MARK, APLOG_TRACE2, 0, c,
ap_log_cerror(APLOG_MARK, APLOG_TRACE2, 0, c,
"Skipping OCSP check for certificate cos no OCSP URL"
" found and no_ocsp_for_cert_ok is set");
return V_OCSP_CERTSTATUS_GOOD;
Expand Down
20 changes: 9 additions & 11 deletions modules/ssl/ssl_engine_vars.c
Original file line number Diff line number Diff line change
Expand Up @@ -343,7 +343,7 @@ char *ssl_var_lookup(apr_pool_t *p, server_rec *s, conn_rec *c, request_rec *r,
return (char *)result;
}

static char *ssl_var_lookup_ssl(apr_pool_t *p, SSLConnRec *sslconn,
static char *ssl_var_lookup_ssl(apr_pool_t *p, SSLConnRec *sslconn,
request_rec *r, char *var)
{
char *result;
Expand Down Expand Up @@ -598,7 +598,7 @@ static char *ssl_var_lookup_ssl_cert_dn(apr_pool_t *p, const X509_NAME *xsname,
var = apr_pstrmemdup(p, var, ptr - var);
raw = 1;
}

/* if an _N suffix is used, find the Nth attribute of given name */
ptr = ap_strchr_c(var, '_');
if (ptr != NULL && strspn(ptr + 1, "0123456789") == strlen(ptr + 1)) {
Expand Down Expand Up @@ -705,19 +705,19 @@ static char *ssl_var_lookup_ssl_cert_remain(apr_pool_t *p, const ASN1_TIME *tm)
/* Fail if the time isn't a valid ASN.1 TIME; RFC3280 mandates
* that the seconds digits are present even though ASN.1
* doesn't. */
if ((tm->type == V_ASN1_UTCTIME && tm->length < 11) ||
(tm->type == V_ASN1_GENERALIZEDTIME && tm->length < 13) ||
if ((ASN1_STRING_type(tm) == V_ASN1_UTCTIME && ASN1_STRING_length(tm) < 11) ||
(ASN1_STRING_type(tm) == V_ASN1_GENERALIZEDTIME && ASN1_STRING_length(tm) < 13) ||
!ASN1_TIME_check(tm)) {
return apr_pstrdup(p, "0");
}

if (tm->type == V_ASN1_UTCTIME) {
exp.tm_year = DIGIT2NUM(tm->data);
if (ASN1_STRING_type(tm) == V_ASN1_UTCTIME) {
exp.tm_year = DIGIT2NUM(ASN1_STRING_get0_data(tm));
if (exp.tm_year <= 50) exp.tm_year += 100;
dp = tm->data + 2;
dp = ASN1_STRING_get0_data(tm) + 2;
} else {
exp.tm_year = DIGIT2NUM(tm->data) * 100 + DIGIT2NUM(tm->data + 2) - 1900;
dp = tm->data + 4;
exp.tm_year = DIGIT2NUM(ASN1_STRING_get0_data(tm)) * 100 + DIGIT2NUM(ASN1_STRING_get0_data(tm) + 2) - 1900;
dp = ASN1_STRING_get0_data(tm) + 4;
}

exp.tm_mon = DIGIT2NUM(dp) - 1;
Expand Down Expand Up @@ -1241,5 +1241,3 @@ static const char *ssl_var_log_handler_x(request_rec *r, char *a)
}
return result;
}