openssl-machine
c721580653
Copyright year updates
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org >
MergeDate: Tue Mar 10 14:37:54 2026
Release: yes
2026-03-10 14:37:52 +00:00
Dr. David von Oheimb
b235c756f1
crypto/{CMS,PKCS7,OCSP,TS,X509}: constify various cert list parameters
...
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com >
Reviewed-by: Frederik Wedel-Heinen <fwh.openssl@gmail.com >
(Merged from https://github.com/openssl/openssl/pull/22304 )
2026-02-04 13:51:19 +01:00
Bob Beck
2fab90bb5e
4.0-POST-CLANG-FORMAT-WEBKIT
...
Reviewed-by: Saša Nedvědický <sashan@openssl.org >
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/29242 )
2025-12-09 00:28:19 -07:00
Caolán McNamara
d5af86a80b
const up various low hanging things
...
to move these symbols out of the .data section
remaining list approx-sorted by size with:
objdump -t libcrypto.so libssl.so | grep -v \\.data.rel.ro | grep \\.data | sort -r -k 4
Reviewed-by: Norbert Pocs <norbertp@openssl.org >
Reviewed-by: Tom Cosgrove <tom.cosgrove@arm.com >
Reviewed-by: Matt Caswell <matt@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/28588 )
2025-11-28 09:36:45 +01:00
Dr. David von Oheimb
d46fca3263
CMP doc: update RFC 4210 -> 9810, RFC 6712 -> 9811
...
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com >
Reviewed-by: Alicja Kario <hkario@redhat.com >
(Merged from https://github.com/openssl/openssl/pull/28017 )
2025-11-19 14:31:42 +01:00
Dr. David von Oheimb
ef63a77758
crypto/{cmp,crmf}/: clean up unneeded #include directives
...
Reviewed-by: Paul Dale <ppzgs1@gmail.com >
Reviewed-by: Tom Cosgrove <tom.cosgrove@arm.com >
(Merged from https://github.com/openssl/openssl/pull/28035 )
2025-08-11 16:33:59 +02:00
openssl-machine
0c679f5566
Copyright year updates
...
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Matt Caswell <matt@openssl.org >
Release: yes
2025-03-12 13:35:59 +00:00
Rajeev Ranjan
0048817523
CMP: add support for central key generation
...
- add testcase for central keygen
- add documentation
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/25132 )
2025-01-27 08:56:46 +01:00
Frederik Wedel-Heinen
35b97122ea
Fixes some memory leaks when errors occur in ossl_cmp_rp_new().
...
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/26235 )
2025-01-27 08:17:27 +01:00
Dr. David von Oheimb
577ec498bd
Fix doc and use of_X509v3_add_extensions() in case sk_X509_EXTENSION_num(exts) <= 0
...
Reviewed-by: Hugo Landau <hlandau@devever.net >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/25631 )
2024-11-13 17:19:58 +01:00
Dr. David von Oheimb
4925af7bb8
add X509v3_add_extensions()
...
Reviewed-by: Neil Horman <nhorman@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/24792 )
2024-07-10 16:19:26 +02:00
Richard Levitte
b646179229
Copyright year updates
...
Reviewed-by: Neil Horman <nhorman@openssl.org >
Release: yes
(cherry picked from commit 0ce7d1f355 )
Reviewed-by: Hugo Landau <hlandau@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/24034 )
2024-04-09 13:43:26 +02:00
Dr. David von Oheimb
bcd3707dba
crypto/cmp: add OSSL_CMP_MSG_get0_certreq_publickey(); fix coding style nit
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com >
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
(Merged from https://github.com/openssl/openssl/pull/21660 )
2024-03-06 08:49:28 +01:00
Dr. David von Oheimb
1d61a03794
crypto/cmp: fix clash of OSSL_CMP_CERTREQID_NONE with error result of ossl_cmp_asn1_get_int()
...
Reviewed-by: Shane Lontis <shane.lontis@oracle.com >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
(Merged from https://github.com/openssl/openssl/pull/20727 )
2023-12-21 23:06:42 +01:00
Dr. David von Oheimb
bedffe1731
crypto/cmp/,apps/lib/cmp_mock_srv.c: various improvements on delayed delivery
...
Reviewed-by: Shane Lontis <shane.lontis@oracle.com >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
(Merged from https://github.com/openssl/openssl/pull/20727 )
2023-12-21 23:06:42 +01:00
Rajeev Ranjan
192bfec487
crypto/cmp/,apps/lib/cmp_mock_srv.c: add delayed delivery for all types of responses
...
Reviewed-by: Shane Lontis <shane.lontis@oracle.com >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
(Merged from https://github.com/openssl/openssl/pull/20727 )
2023-12-21 22:53:35 +01:00
Matt Caswell
da1c088f59
Copyright year updates
...
Reviewed-by: Richard Levitte <levitte@openssl.org >
Release: yes
2023-09-07 09:59:15 +01:00
Rajeev Ranjan
1d32ec20fe
CMP: support specifying certificate to be revoked via issuer and serial number
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com >
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
(Merged from https://github.com/openssl/openssl/pull/21116 )
2023-07-10 08:03:38 +02:00
Dr. David von Oheimb
d477484d33
CMP: add support for genm/genp messages with id-it-caCerts
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Paul Dale <pauli@openssl.org >
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
(Merged from https://github.com/openssl/openssl/pull/19231 )
2023-06-01 09:39:12 +02:00
Dr. David von Oheimb
e0f1ec3b2e
CMP client: fix checking new cert enrolled with oldcert and without private key
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Todd Short <todd.short@me.com >
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
(Merged from https://github.com/openssl/openssl/pull/20832 )
2023-05-12 10:46:27 +02:00
Dr. David von Oheimb
2d6585986f
CMP client: fix error response on -csr without private key, also in docs
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Todd Short <todd.short@me.com >
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
(Merged from https://github.com/openssl/openssl/pull/20832 )
2023-05-12 10:46:27 +02:00
Dr. David von Oheimb
25b18e629d
crypto/cmp: fix CertReqId to use in p10cr transactions acc. to RFC 4210
...
Reviewed-by: Paul Dale <pauli@openssl.org >
Reviewed-by: Tom Cosgrove <tom.cosgrove@arm.com >
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
(Merged from https://github.com/openssl/openssl/pull/20298 )
2023-04-18 07:26:11 +02:00
Dr. David von Oheimb
4b0c27d445
CMP add: fix -reqin option, which requires adding OSSL_CMP_MSG_update_recipNonce()
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Paul Dale <pauli@openssl.org >
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
(Merged from https://github.com/openssl/openssl/pull/20204 )
2023-03-25 09:55:26 +01:00
JAVAID Mohammad-Habib
c9c99018a8
cmp_msg.c: free memory of certStatus before goto err
...
CLA: trivial
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/20406 )
2023-03-20 19:02:44 +01:00
Dr. David von Oheimb
7e3034939b
CMP: fix gen_new() in cmp_msg.c checking wrong ITAVs
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Paul Dale <pauli@openssl.org >
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
(Merged from https://github.com/openssl/openssl/pull/19216 )
2022-11-25 09:15:37 +01:00
Dr. David von Oheimb
19ddcc4cbb
CMP: fix status held in OSSL_CMP_CTX, in particular for genp messages
...
On this occasion, replace magic constants by mnemonic ones; update doc
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Todd Short <todd.short@me.com >
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
(Merged from https://github.com/openssl/openssl/pull/19205 )
2022-11-24 14:00:46 +01:00
Dr. David von Oheimb
357bfe7345
CMP+CRMF: fix formatting nits in crypto/, include/, and test/
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com >
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
(Merged from https://github.com/openssl/openssl/pull/19230 )
2022-11-24 13:45:06 +01:00
Richard Levitte
e077455e9e
Stop raising ERR_R_MALLOC_FAILURE in most places
...
Since OPENSSL_malloc() and friends report ERR_R_MALLOC_FAILURE, and
at least handle the file name and line number they are called from,
there's no need to report ERR_R_MALLOC_FAILURE where they are called
directly, or when SSLfatal() and RLAYERfatal() is used, the reason
`ERR_R_MALLOC_FAILURE` is changed to `ERR_R_CRYPTO_LIB`.
There were a number of places where `ERR_R_MALLOC_FAILURE` was reported
even though it was a function from a different sub-system that was
called. Those places are changed to report ERR_R_{lib}_LIB, where
{lib} is the name of that sub-system.
Some of them are tricky to get right, as we have a lot of functions
that belong in the ASN1 sub-system, and all the `sk_` calls or from
the CRYPTO sub-system.
Some extra adaptation was necessary where there were custom OPENSSL_malloc()
wrappers, and some bugs are fixed alongside these changes.
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Hugo Landau <hlandau@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/19301 )
2022-10-05 14:02:03 +02:00
Dr. David von Oheimb
7af110f9f5
CMP: correct handling of fallback subject in OSSL_CMP_CTX_setup_CRM() and its doc
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Matt Caswell <matt@openssl.org >
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
(Merged from https://github.com/openssl/openssl/pull/18929 )
2022-08-24 11:29:40 +02:00
Dr. David von Oheimb
74107c4428
CMP: implement optional hashAlg field of certConf CMPv3 message
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Paul Dale <pauli@openssl.org >
Reviewed-by: Hugo Landau <hlandau@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/18294 )
2022-07-01 07:38:50 +01:00
Matt Caswell
fecb3aae22
Update copyright year
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Release: yes
2022-05-03 13:34:51 +01:00
Dr. David von Oheimb
c8c923454b
OSSL_CMP_CTX_setup_CRM(): Fix handling of defaults from CSR and refcert
...
Also update and complete related documentation.
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Paul Dale <pauli@openssl.org >
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com >
(Merged from https://github.com/openssl/openssl/pull/17726 )
2022-03-12 09:05:02 +01:00
Dr. David von Oheimb
d580c2790f
OSSL_CMP_MSG_read(): Fix mem leak on file read error
...
Reviewed-by: Paul Dale <pauli@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/17225 )
2021-12-09 07:44:29 +01:00
x2018
1287dabd0b
fix some code with obvious wrong coding style
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Richard Levitte <levitte@openssl.org >
Reviewed-by: Paul Dale <pauli@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/16918 )
2021-10-28 13:10:46 +10:00
Matt Caswell
95f8c1e142
Fix CMP code to not assume NUL terminated strings
...
ASN.1 strings may not be NUL terminated. Don't assume they are.
CVE-2021-3712
Reviewed-by: Viktor Dukhovni <viktor@openssl.org >
Reviewed-by: Paul Dale <pauli@openssl.org >
Reviewed-by: David Benjamin <davidben@google.com >
2021-08-24 14:22:06 +01:00
Dr. David von Oheimb
7df56adac7
CMP: Add missing getter functions to CRMF API and CMP API
...
Reviewed-by: Tim Hudson <tjh@openssl.org >
Reviewed-by: Paul Dale <pauli@openssl.org >
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/15790 )
2021-06-30 10:38:23 +02:00
Dr. David von Oheimb
6eaf139f62
ossl_cmp_error_new(): Fix Coverity issue 1486534, and consequently also issues 1486536 and 1486533
...
The issues are due to an integer overflow that may happen on '(ERR_SYSTEM_FLAG << 1)'.
Reviewed-by: Paul Dale <pauli@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/15938 )
2021-06-29 13:05:52 +02:00
Dr. David von Oheimb
991519aeb9
CMP: Improve reporting of error codes and related strings via 'error' msg
...
Reviewed-by: Paul Dale <pauli@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/15879 )
2021-06-25 07:44:50 +02:00
Dr. David von Oheimb
7b3990e3f8
CMP: Clean up internal message creation API and its documentation
...
Reviewed-by: Paul Dale <pauli@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/15879 )
2021-06-25 07:44:50 +02:00
Dr. David von Oheimb
eefdb8e013
X509_digest_sig(): Improve default hash for EdDSA and allow to return the chosen default
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
Reviewed-by: Paul Dale <pauli@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/15762 )
2021-06-16 14:30:35 +01:00
Matt Caswell
c631378058
Use the new ASN.1 libctx aware capabilities in CMP
...
Make sure we pass the libctx/propq around everywhere that we need it to
ensure we get provider keys when needed.
Reviewed-by: Shane Lontis <shane.lontis@oracle.com >
Reviewed-by: Paul Dale <pauli@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/15591 )
2021-06-05 17:39:10 +10:00
Pauli
75e1191f4d
cmp: remove TODOs
...
Reviewed-by: Tim Hudson <tjh@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/15539 )
2021-06-02 16:30:15 +10:00
Shane Lontis
4669015d7b
Add ossl_ x509 symbols
...
Partial fix for #12964
Reviewed-by: Paul Dale <pauli@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/14473 )
2021-03-18 17:52:38 +10:00
Dr. David von Oheimb
dd5fa5f5af
CMP: On NULL-DN subject or issuer input omit field in cert template
...
Also improve diagnostics on inconsistent cert request input in apps/cmp.c,
add trace output for transactionIDs on new sessions,
and update the documentation in openssl-cmp.pod.in.
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/14018 )
2021-03-02 11:05:34 +01:00
Dr. David von Oheimb
5e128ed120
CMP: Fix total_timeout behavior; small doc and diagnostic improvements
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/14019 )
2021-02-19 16:58:22 +01:00
Dr. David von Oheimb
daf1300b80
Add internal X509_add_certs_new(), which simplifies matters
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/14039 )
2021-02-18 16:50:12 +01:00
Richard Levitte
4333b89f50
Update copyright year
...
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/13999 )
2021-01-28 13:54:57 +01:00
Dr. David von Oheimb
3d46c81a7d
CMP: Allow PKCS#10 input also for ir, cr, kur, and rr messages
...
Also update documentation regarding sources of certs and keys,
improve type of OSSL_CMP_exec_RR_ses(),
add tests for CSR-based cert revocation
Reviewed-by: Tomas Mraz <tomas@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/13841 )
2021-01-21 17:53:26 +01:00
Dr. David von Oheimb
f87ead9801
ossl_cmp_certreq_new(): Fix POPO key mismatch in case newPkey is just public key
...
Reviewed-by: Matt Caswell <matt@openssl.org >
(Merged from https://github.com/openssl/openssl/pull/13409 )
2020-11-20 13:36:30 +01:00
Richard Levitte
a150f8e1fc
CRYPTO: refactor ERR_raise()+ERR_add_error_data() to ERR_raise_data()
...
This is not done absolutely everywhere, as there are places where
the use of ERR_add_error_data() is quite complex, but at least the
simple cases are done.
Reviewed-by: Paul Dale <paul.dale@oracle.com >
(Merged from https://github.com/openssl/openssl/pull/13318 )
2020-11-13 09:35:31 +01:00