Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 19 additions & 4 deletions src/ocsp.c
Original file line number Diff line number Diff line change
Expand Up @@ -1228,22 +1228,37 @@ OcspResponse* wolfSSL_d2i_OCSP_RESPONSE(OcspResponse** response,
goto error;

if (resp->single != NULL) {
FreeOcspEntry(resp->single, NULL);
XFREE(resp->single, NULL, DYNAMIC_TYPE_OCSP_ENTRY);
OcspEntry* s = resp->single;

/* Release the whole SingleResponse chain, as
* wolfSSL_OCSP_RESPONSE_free() does. Every entry after the first was
* allocated by the previous decode and FreeOcspEntry() on its own
* only reaches the head. */
while (s != NULL) {
OcspEntry* sNext = s->next;

FreeOcspEntry(s, NULL);
XFREE(s, NULL, DYNAMIC_TYPE_OCSP_ENTRY);
s = sNext;
}
}
resp->single = (OcspEntry*)XMALLOC(sizeof(OcspEntry), NULL,
DYNAMIC_TYPE_OCSP_ENTRY);
if (resp->single == NULL)
goto error;
/* Zeroed before the next allocation can fail: the error path walks it. */
XMEMSET(resp->single, 0, sizeof(OcspEntry));
resp->single->status = (CertStatus*)XMALLOC(sizeof(CertStatus), NULL,
DYNAMIC_TYPE_OCSP_STATUS);
if (resp->single->status == NULL)
goto error;
/* Leave the object in the state a fresh one is in. On reuse the response,
* cert, sig, sigParams and nonce references all pointed into the source
* buffer released above, and the new encoding need not set them again. */
InitOcspResponse(resp, resp->single, resp->single->status, resp->source,
(word32)len, resp->heap);
resp->single->ownStatus = 1;
XMEMSET(resp->single->status, 0, sizeof(CertStatus));
XMEMCPY(resp->source, *data, (size_t)len);
resp->maxIdx = (word32)len;

ret = OcspResponseDecode(resp, NULL, NULL, 1, 1);
if (ret != 0 && ret != WC_NO_ERR_TRACE(ASN_OCSP_CONFIRM_E)) {
Expand Down
44 changes: 44 additions & 0 deletions src/tls.c
Original file line number Diff line number Diff line change
Expand Up @@ -16786,6 +16786,50 @@ int TLSX_PopulateExtensions(WOLFSSL* ssl, byte isServer)
#endif
#endif /* HAVE_SUPPORTED_CURVES */

#ifdef HAVE_CERTIFICATE_STATUS_REQUEST
/* A status_request configured on the context holds the OCSP nonce
* generated when it was configured, so every ClientHello would carry
* the same nonce. Give the connection its own copy with a fresh nonce
* instead. */
if (TLSX_Find(ssl->extensions, TLSX_STATUS_REQUEST) == NULL) {
TLSX* csrExt = TLSX_Find(ssl->ctx->extensions, TLSX_STATUS_REQUEST);
CertificateStatusRequest* csr = csrExt ?
(CertificateStatusRequest*)csrExt->data : NULL;

if (csr != NULL && (csr->options & WOLFSSL_CSR_OCSP_USE_NONCE)) {
ret = TLSX_UseCertificateStatusRequest(&ssl->extensions,
csr->status_type, csr->options, ssl,
ssl->heap, ssl->devId);
if (ret != WOLFSSL_SUCCESS)
return ret;
}
}
#endif /* HAVE_CERTIFICATE_STATUS_REQUEST */
#ifdef HAVE_CERTIFICATE_STATUS_REQUEST_V2
/* Same for status_request_v2. The connection level list replaces the
* context level one on the wire, so copy every item. */
Comment thread
kareem-wolfssl marked this conversation as resolved.
if (TLSX_Find(ssl->extensions, TLSX_STATUS_REQUEST_V2) == NULL) {
TLSX* csr2Ext = TLSX_Find(ssl->ctx->extensions,
TLSX_STATUS_REQUEST_V2);
CertificateStatusRequestItemV2* csr2 = csr2Ext ?
(CertificateStatusRequestItemV2*)csr2Ext->data : NULL;
CertificateStatusRequestItemV2* item;
int useNonce = 0;

for (item = csr2; item != NULL; item = item->next) {
if (item->options & WOLFSSL_CSR2_OCSP_USE_NONCE)
useNonce = 1;
}
for (item = csr2; useNonce && item != NULL; item = item->next) {
ret = TLSX_UseCertificateStatusRequestV2(&ssl->extensions,
item->status_type, item->options,
ssl->heap, ssl->devId);
if (ret != WOLFSSL_SUCCESS)
return ret;
}
}
#endif /* HAVE_CERTIFICATE_STATUS_REQUEST_V2 */

#ifdef WOLFSSL_SRTP
if (ssl->options.dtls && ssl->dtlsSrtpProfiles != 0) {
WOLFSSL_MSG("Adding DTLS SRTP extension");
Expand Down
5 changes: 5 additions & 0 deletions tests/api.c
Original file line number Diff line number Diff line change
Expand Up @@ -44173,6 +44173,11 @@ TEST_CASE testCases[] = {
TEST_DECL(test_ocsp_status_callback),
TEST_DECL(test_ocsp_status_request_scr),
TEST_DECL_GROUP("ocsp", test_ocsp_basic_verify),
TEST_DECL_GROUP("ocsp", test_ocsp_d2i_reuse_clears_refs),
TEST_DECL_GROUP("ocsp", test_ocsp_d2i_reuse_frees_single_chain),
TEST_DECL_GROUP("ocsp", test_ocsp_ctx_stapling_nonce_per_connection),
TEST_DECL_GROUP("ocsp",
test_ocsp_ctx_stapling_v2_nonce_per_connection),
TEST_DECL_GROUP("ocsp", test_ocsp_ancestor_responder_rejected),
TEST_DECL_GROUP("ocsp", test_ocsp_forged_responder_cert_rejected),
TEST_DECL_GROUP("ocsp", test_ocsp_responder_keyhash_binding),
Expand Down
Loading
Loading