SSL: avoid matching IP addresses in dNSName and commonName

OpenSSL 1.0.2+ validates IP addresses only against iPAddress
subjectAltName entries via X509_check_ip().  For older OpenSSL
versions, equivalent validation is now performed.

Note that dNSName entries are still logged when checking an IP
address, they are not used for matching.

Co-authored-by: Sergey Kandaurov <pluknet@nginx.com>
This commit is contained in:
Eugene GrebenschikovandSergey Kandaurov authored and Eugene committed 2026-09-24 12:33:26 -07:00
1 parent 4f86b96da9
commit d10dd3123a
1 file changed
+7 -1
+7 -1
View File
@@ -5415,7 +5415,7 @@ ngx_ssl_check_host(ngx_connection_t *c, ngx_str_t *name)
(size_t) ASN1_STRING_length(str),
ASN1_STRING_data(str));
if (ngx_ssl_check_name(name, str) == NGX_OK) {
if (addr == NULL && ngx_ssl_check_name(name, str) == NGX_OK) {
ngx_log_debug0(NGX_LOG_DEBUG_EVENT, c->log, 0,
"SSL subjectAltName: match");
GENERAL_NAMES_free(altnames);
@@ -5479,6 +5479,12 @@ ngx_ssl_check_host(ngx_connection_t *c, ngx_str_t *name)
* CN, both Apache and OpenSSL check all CNs, and so do we.
*/
if (addr) {
ngx_log_debug0(NGX_LOG_DEBUG_EVENT, c->log, 0,
"SSL commonName: no match");
goto failed;
}
sname = X509_get_subject_name(cert);
if (sname == NULL) {