mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
pv: download_first_crl_from_x509: Increase the timeout to 10s
3-second timeout might be too short for slow networks therefore increase it to 10s. In addition move this constant to a more prominent position and add documentation. Assisted-by: IBM Bob:1.0.5 Signed-off-by: Marc Hartmayer <marc@linux.ibm.com> Reviewed-by: Steffen Eiden <seiden@linux.ibm.com> Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
This commit is contained in:
committed by
Jan Höppner
parent
5feee12827
commit
cdc787d92d
@@ -56,6 +56,19 @@ const SECURITY_CHAIN_MAX_LEN: c_int = 2;
|
||||
/// while preventing abuse.
|
||||
const CRL_MAX_REDIRECTIONS: usize = 10;
|
||||
|
||||
/// Maximum timeout duration for CRL (Certificate Revocation List) downloads.
|
||||
///
|
||||
/// This timeout applies to individual CRL download operations to prevent
|
||||
/// indefinite blocking when fetching revocation information from remote servers.
|
||||
///
|
||||
/// # Value
|
||||
///
|
||||
/// Set to 10 seconds, which provides a reasonable balance between:
|
||||
/// - Allowing sufficient time for legitimate CRL downloads over slow networks
|
||||
/// - Preventing excessive delays in certificate verification workflows
|
||||
/// - Protecting against unresponsive or malicious CRL distribution points
|
||||
const CRL_TIMEOUT_MAX: Duration = Duration::from_secs(10);
|
||||
|
||||
/// Verifies that the HKD
|
||||
/// * has enough security bits
|
||||
/// * is inside its validity period
|
||||
@@ -471,10 +484,7 @@ fn download_first_crl_from_x509_impl<H: HttpClient>(
|
||||
cert: &X509Ref,
|
||||
mut client: H,
|
||||
) -> Result<Option<Vec<openssl::x509::X509Crl>>> {
|
||||
use std::time::Duration;
|
||||
|
||||
use crate::utils::read_crls;
|
||||
const CRL_TIMEOUT_MAX: Duration = Duration::from_secs(3);
|
||||
|
||||
'outer: for dist_point_url in x509_dist_points(cert) {
|
||||
// Validate protocol BEFORE attempting download
|
||||
|
||||
Reference in New Issue
Block a user