Commit 352c8aa
committed
ssl: Skip undecodable certificate_authorities names
The TLS CertificateRequest certificate_authorities list is only a hint for client certificate selection. Some real servers advertise CA names that violate PKIX type constraints, for example countryName encoded as UTF8String.
Previously ssl_handshake decoded every advertised CA name with public_key:pkix_normalize_name/1. One malformed advisory name could therefore abort the whole handshake with a fatal decode_error, even when the client had no certificate configured.
Catch normalization failures and drop only the bad CA name, keeping any valid names in the list. Add a regression test covering a malformed DN from GH-11338 alongside a valid CA name.
Fixes #113381 parent fef08ae commit 352c8aa
2 files changed
Lines changed: 37 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3480 | 3480 | | |
3481 | 3481 | | |
3482 | 3482 | | |
3483 | | - | |
| 3483 | + | |
| 3484 | + | |
| 3485 | + | |
| 3486 | + | |
| 3487 | + | |
| 3488 | + | |
| 3489 | + | |
3484 | 3490 | | |
3485 | 3491 | | |
3486 | 3492 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
55 | 55 | | |
56 | 56 | | |
57 | 57 | | |
58 | | - | |
| 58 | + | |
| 59 | + | |
59 | 60 | | |
60 | 61 | | |
61 | 62 | | |
| |||
70 | 71 | | |
71 | 72 | | |
72 | 73 | | |
73 | | - | |
| 74 | + | |
| 75 | + | |
74 | 76 | | |
75 | 77 | | |
76 | 78 | | |
| |||
294 | 296 | | |
295 | 297 | | |
296 | 298 | | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
| 313 | + | |
| 314 | + | |
| 315 | + | |
| 316 | + | |
| 317 | + | |
| 318 | + | |
297 | 319 | | |
298 | 320 | | |
299 | 321 | | |
| |||
302 | 324 | | |
303 | 325 | | |
304 | 326 | | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
| 331 | + | |
| 332 | + | |
0 commit comments