SL-13910 Added the TLS Web Server Authentication certificate check
parent
e8b31d03b4
commit
645393c5e9
|
|
@ -75,6 +75,7 @@
|
|||
|
||||
#define CERT_EXTENDED_KEY_USAGE "extendedKeyUsage"
|
||||
#define CERT_EKU_SERVER_AUTH SN_server_auth
|
||||
#define CERT_EKU_TLS_SERVER_AUTH LN_server_auth
|
||||
|
||||
#define CERT_SUBJECT_KEY_IDENTFIER "subjectKeyIdentifier"
|
||||
#define CERT_AUTHORITY_KEY_IDENTIFIER "authorityKeyIdentifier"
|
||||
|
|
|
|||
|
|
@ -925,8 +925,11 @@ void _validateCert(int validation_policy,
|
|||
}
|
||||
// only validate EKU if the cert has it
|
||||
if(current_cert_info.has(CERT_EXTENDED_KEY_USAGE) && current_cert_info[CERT_EXTENDED_KEY_USAGE].isArray() &&
|
||||
(!_LLSDArrayIncludesValue(current_cert_info[CERT_EXTENDED_KEY_USAGE],
|
||||
LLSD((std::string)CERT_EKU_SERVER_AUTH))))
|
||||
( (!_LLSDArrayIncludesValue(current_cert_info[CERT_EXTENDED_KEY_USAGE],
|
||||
LLSD((std::string)CERT_EKU_SERVER_AUTH)))
|
||||
|| (!_LLSDArrayIncludesValue(current_cert_info[CERT_EXTENDED_KEY_USAGE],
|
||||
LLSD((std::string)CERT_EKU_TLS_SERVER_AUTH)))
|
||||
))
|
||||
{
|
||||
LLTHROW(LLCertKeyUsageValidationException(current_cert_info));
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue