mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
pv: Defer CRL downloads until certificate validation succeeds
Perform certificate verification in two stages. First, verify the
certificate chain without CRL checks. Once the chain has been validated,
download the referenced CRLs and repeat the verification with CRL
checking enabled.
Fixes: c6f621d0dc ("rust: Add library for pv tools")
Signed-off-by: Marc Hartmayer <marc@linux.ibm.com>
Reviewed-by: Steffen Eiden <seiden@linux.ibm.com>
Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
This commit is contained in:
committed by
Jan Höppner
parent
cdc787d92d
commit
187437c6c8
+33
-13
@@ -5,7 +5,7 @@
|
||||
use core::slice;
|
||||
use std::path::Path;
|
||||
|
||||
use helper::download_first_crl_from_x509;
|
||||
use helper::{download_first_crl_from_x509, StoreSetupMode};
|
||||
use log::{debug, trace};
|
||||
use openssl::error::ErrorStack;
|
||||
use openssl::stack::Stack;
|
||||
@@ -181,25 +181,45 @@ impl CertVerifier {
|
||||
Q: AsRef<Path>,
|
||||
R: AsRef<Path>,
|
||||
{
|
||||
let mut store = helper::store_setup(root_ca_path, crl_paths, cert_paths)?;
|
||||
let mut untr_certs = Vec::with_capacity(cert_paths.len());
|
||||
for path in cert_paths {
|
||||
let mut crt = read_certs(&read_file(path, "certificate")?)?;
|
||||
if !offline {
|
||||
for c in &crt {
|
||||
if let Some(crl) = download_first_crl_from_x509(c)? {
|
||||
crl.iter().try_for_each(|c| store.add_crl(c))?;
|
||||
}
|
||||
}
|
||||
}
|
||||
untr_certs.append(&mut crt);
|
||||
}
|
||||
let (ibm_z_sign_key, chain) = helper::extract_ibm_sign_key(untr_certs.clone())?;
|
||||
|
||||
// remove the IBM signing certificate from chain.
|
||||
// We have to verify them separately as they are not marked as intermediate certs
|
||||
let (ibm_z_sign_key, chain) = helper::extract_ibm_sign_key(untr_certs)?;
|
||||
// Two-round verification:
|
||||
//
|
||||
// Round 1: Verify chain without CRL checks before downloading files
|
||||
// from URLs from (yet) untrusted certificates.
|
||||
let store_builder = helper::store_setup(
|
||||
root_ca_path.as_ref(),
|
||||
crl_paths,
|
||||
cert_paths,
|
||||
StoreSetupMode::WithoutCrlCheck,
|
||||
)?;
|
||||
helper::verify_chain(
|
||||
&store_builder.build(),
|
||||
&chain,
|
||||
slice::from_ref(&ibm_z_sign_key),
|
||||
)?;
|
||||
|
||||
let store = store.build();
|
||||
// Round 2: Download CRLs and verify again, but this time with CRL checks
|
||||
let mut store_builder = helper::store_setup(
|
||||
root_ca_path,
|
||||
crl_paths,
|
||||
cert_paths,
|
||||
StoreSetupMode::WithCrlCheck,
|
||||
)?;
|
||||
if !offline {
|
||||
for cert in &untr_certs {
|
||||
if let Some(crls) = download_first_crl_from_x509(cert)? {
|
||||
crls.iter().try_for_each(|c| store_builder.add_crl(c))?;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
let store = store_builder.build();
|
||||
helper::verify_chain(&store, &chain, slice::from_ref(&ibm_z_sign_key))?;
|
||||
|
||||
Ok(Self {
|
||||
|
||||
Reference in New Issue
Block a user