[crypto] Use certificate's own public key algorithm for key matching

When finding the certificate corresponding to a private key, the match
is currently performed using the certificate's signature algorithm
(i.e. the public key algorithm of the issuer's key) rather than the
certificate's own public key algorithm.  This breaks key matching for
heterogenous certificate chains (e.g. an ECDSA client certificate
issued by an RSA intermediate certificate).

Fix by using the certificate's own public key algorithm.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
This commit is contained in:
Michael Brown
2026-09-20 14:39:41 +01:00
parent cff60d28d6
commit cbdb57278d
+1 -1
View File
@@ -1866,7 +1866,7 @@ struct x509_certificate * x509_find_key ( struct x509_chain *store,
/* Check public key */ /* Check public key */
cert = link->cert; cert = link->cert;
if ( pubkey_match ( cert->signature_algorithm->pubkey, if ( pubkey_match ( cert->subject.public_key.algorithm->pubkey,
privkey_cursor ( key ), privkey_cursor ( key ),
&cert->subject.public_key.raw ) == 0 ) &cert->subject.public_key.raw ) == 0 )
return x509_found ( store, cert ); return x509_found ( store, cert );