mirror of
https://github.com/ipxe/ipxe
synced 2026-10-07 15:05:42 +03:00
[crypto] Use certificate's own public key algorithm for key matching
When finding the certificate corresponding to a private key, the match is currently performed using the certificate's signature algorithm (i.e. the public key algorithm of the issuer's key) rather than the certificate's own public key algorithm. This breaks key matching for heterogenous certificate chains (e.g. an ECDSA client certificate issued by an RSA intermediate certificate). Fix by using the certificate's own public key algorithm. Signed-off-by: Michael Brown <mcb30@ipxe.org>
This commit is contained in:
+1
-1
@@ -1866,7 +1866,7 @@ struct x509_certificate * x509_find_key ( struct x509_chain *store,
|
|||||||
|
|
||||||
/* Check public key */
|
/* Check public key */
|
||||||
cert = link->cert;
|
cert = link->cert;
|
||||||
if ( pubkey_match ( cert->signature_algorithm->pubkey,
|
if ( pubkey_match ( cert->subject.public_key.algorithm->pubkey,
|
||||||
privkey_cursor ( key ),
|
privkey_cursor ( key ),
|
||||||
&cert->subject.public_key.raw ) == 0 )
|
&cert->subject.public_key.raw ) == 0 )
|
||||||
return x509_found ( store, cert );
|
return x509_found ( store, cert );
|
||||||
|
|||||||
Reference in New Issue
Block a user