summaryrefslogtreecommitdiff
path: root/curvetun_mgmt_servers.h
AgeCommit message (Expand)AuthorFilesLines
2013-07-11curvetun: renamed client, server, and management filesDaniel Borkmann1-0/+15
>2016-07-18 00:10:55 +0100 committerJames Morris <james.l.morris@oracle.com>2016-07-18 12:19:47 +1000 commitacddc72015e5bc8f640b02d38b36afd7841c9c14 (patch) tree1be27dee2805638585dd161d1f402136341c6f85 parentd128471a14775cd11abd81c09b2a086997ab3150 (diff)
KEYS: Fix for erroneous trust of incorrectly signed X.509 certs
Arbitrary X.509 certificates without authority key identifiers (AKIs) can be added to "trusted" keyrings, including IMA or EVM certs loaded from the filesystem. Signature verification is currently bypassed for certs without AKIs. Trusted keys were recently refactored, and this bug is not present in 4.6. restrict_link_by_signature should return -ENOKEY (no matching parent certificate found) if the certificate being evaluated has no AKIs, instead of bypassing signature checks and returning 0 (new certificate accepted). Reported-by: Petko Manolov <petkan@mip-labs.com> Signed-off-by: Mat Martineau <mathew.j.martineau@linux.intel.com> Signed-off-by: David Howells <dhowells@redhat.com> Signed-off-by: James Morris <james.l.morris@oracle.com>
Diffstat