mirror of
https://github.com/nginx/nginx.git
synced 2026-10-05 05:36:56 -05:00
SSL: avoid matching IP addresses in dNSName and commonName
OpenSSL 1.0.2+ validates IP addresses only against iPAddress subjectAltName entries via X509_check_ip(). For older OpenSSL versions, equivalent validation is now performed. Note that dNSName entries are still logged when checking an IP address, they are not used for matching. Co-authored-by: Sergey Kandaurov <pluknet@nginx.com>
This commit is contained in:
1 parent
4f86b96da9
commit
d10dd3123a
1 file changed
+7
-1
@@ -5415,7 +5415,7 @@ ngx_ssl_check_host(ngx_connection_t *c, ngx_str_t *name)
|
||||
(size_t) ASN1_STRING_length(str),
|
||||
ASN1_STRING_data(str));
|
||||
|
||||
if (ngx_ssl_check_name(name, str) == NGX_OK) {
|
||||
if (addr == NULL && ngx_ssl_check_name(name, str) == NGX_OK) {
|
||||
ngx_log_debug0(NGX_LOG_DEBUG_EVENT, c->log, 0,
|
||||
"SSL subjectAltName: match");
|
||||
GENERAL_NAMES_free(altnames);
|
||||
@@ -5479,6 +5479,12 @@ ngx_ssl_check_host(ngx_connection_t *c, ngx_str_t *name)
|
||||
* CN, both Apache and OpenSSL check all CNs, and so do we.
|
||||
*/
|
||||
|
||||
if (addr) {
|
||||
ngx_log_debug0(NGX_LOG_DEBUG_EVENT, c->log, 0,
|
||||
"SSL commonName: no match");
|
||||
goto failed;
|
||||
}
|
||||
|
||||
sname = X509_get_subject_name(cert);
|
||||
|
||||
if (sname == NULL) {
|
||||
|
||||
Reference in new issue
Block a user