mirror of
https://github.com/emmansun/gmsm.git
synced 2025-04-27 04:36:19 +08:00
[sync] crypto/x509: restrict CRL number to <=20 octets #69
This commit is contained in:
parent
99bfac3a2b
commit
7e81d05ce9
@ -1909,6 +1909,9 @@ func CreateRevocationList(rand io.Reader, template *x509.RevocationList, issuer
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
if numBytes := template.Number.Bytes(); len(numBytes) > 20 || (len(numBytes) == 20 && numBytes[0]&0x80 != 0) {
|
||||||
|
return nil, errors.New("x509: CRL number exceeds 20 octets")
|
||||||
|
}
|
||||||
crlNum, err := asn1.Marshal(template.Number)
|
crlNum, err := asn1.Marshal(template.Number)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
|
@ -1789,6 +1789,40 @@ func TestCreateRevocationList(t *testing.T) {
|
|||||||
},
|
},
|
||||||
expectedError: "x509: template contains nil Number field",
|
expectedError: "x509: template contains nil Number field",
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
name: "long Number",
|
||||||
|
key: sm2Priv,
|
||||||
|
issuer: &x509.Certificate{
|
||||||
|
KeyUsage: KeyUsageCRLSign,
|
||||||
|
Subject: pkix.Name{
|
||||||
|
CommonName: "testing",
|
||||||
|
},
|
||||||
|
SubjectKeyId: []byte{1, 2, 3},
|
||||||
|
},
|
||||||
|
template: &x509.RevocationList{
|
||||||
|
ThisUpdate: time.Time{}.Add(time.Hour * 24),
|
||||||
|
NextUpdate: time.Time{}.Add(time.Hour * 48),
|
||||||
|
Number: big.NewInt(0).SetBytes(append([]byte{1}, make([]byte, 20)...)),
|
||||||
|
},
|
||||||
|
expectedError: "x509: CRL number exceeds 20 octets",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "long Number (20 bytes, MSB set)",
|
||||||
|
key: sm2Priv,
|
||||||
|
issuer: &x509.Certificate{
|
||||||
|
KeyUsage: KeyUsageCRLSign,
|
||||||
|
Subject: pkix.Name{
|
||||||
|
CommonName: "testing",
|
||||||
|
},
|
||||||
|
SubjectKeyId: []byte{1, 2, 3},
|
||||||
|
},
|
||||||
|
template: &x509.RevocationList{
|
||||||
|
ThisUpdate: time.Time{}.Add(time.Hour * 24),
|
||||||
|
NextUpdate: time.Time{}.Add(time.Hour * 48),
|
||||||
|
Number: big.NewInt(0).SetBytes(append([]byte{255}, make([]byte, 19)...)),
|
||||||
|
},
|
||||||
|
expectedError: "x509: CRL number exceeds 20 octets",
|
||||||
|
},
|
||||||
{
|
{
|
||||||
name: "invalid signature algorithm",
|
name: "invalid signature algorithm",
|
||||||
key: sm2Priv,
|
key: sm2Priv,
|
||||||
|
Loading…
x
Reference in New Issue
Block a user