Skip to content

fix crypto: use only the pinned certificate in CmsVerifier - #1353

Closed
netliomax25-code wants to merge 1 commit into
userver-framework:developfrom
netliomax25-code:cms-verifier-nointern
Closed

netliomax25-code wants to merge 1 commit into
userver-framework:developfrom
netliomax25-code:cms-verifier-nointern

Conversation

@netliomax25-code

Copy link
Copy Markdown
Contributor
  1. CmsVerifier hands the pinned certificate to CMS_verify as the certs stack with a null store, but ToNativeCmsFlags never sets CMS_NOINTERN, so when the SignerInfo does not match the pinned certificate OpenSSL falls back to the certificates embedded in the message itself.
  2. With a null store, signer chain verification cannot succeed, so callers have to pass kNoSignerCertVerify, and in that mode CMS_verify never checks that the resolved signer is the pinned certificate. A message signed with any key whose certificate is embedded (the CMS_sign default) is accepted by a verifier pinned to an unrelated certificate, in DER, PEM and S/MIME forms.
  3. Start the native flags from CMS_NOINTERN so the signer certificate is only ever resolved from the pinned certificate. Messages signed by the pinned certificate, with or without the certificate embedded, verify as before.

Added two signature_test.cpp regressions: a foreign-signer message now throws VerificationError in all three input forms (it verified successfully on the current tree), and a message that embeds the pinned certificate itself still verifies. The full universal unittest suite passes under the addr/ub sanitizer build.

@apolukhin

Copy link
Copy Markdown
Member

LGTM

@robot-magpie

robot-magpie Bot commented Oct 2, 2026

Copy link
Copy Markdown

Many thanks for the PR! @apolukhin is now importing your pull request into our internal upstream repository.

@robot-magpie

robot-magpie Bot commented Oct 7, 2026

Copy link
Copy Markdown

✅ This pull request is being closed because it has been successfully merged into our internal monorepository.
Your changes will be pushed to this repository soon. Thank you for your contribution!

@robot-magpie robot-magpie Bot closed this Oct 7, 2026
robot-piglet pushed a commit that referenced this pull request Oct 7, 2026
1. CmsVerifier hands the pinned certificate to CMS_verify as the certs stack with a null store, but ToNativeCmsFlags never sets CMS_NOINTERN, so when the SignerInfo does not match the pinned certificate OpenSSL falls back to the certificates embedded in the message itself.
2. With a null store, signer chain verification cannot succeed, so callers have to pass kNoSignerCertVerify, and in that mode CMS_verify never checks that the resolved signer is the pinned certificate. A message signed with any key whose certificate is embedded (the CMS_sign default) is accepted by a verifier pinned to an unrelated certificate, in DER, PEM and S/MIME forms.
3. Start the native flags from CMS_NOINTERN so the signer certificate is only ever resolved from the pinned certificate. Messages signed by the pinned certificate, with or without the certificate embedded, verify as before.

Added two signature_test.cpp regressions: a foreign-signer message now throws VerificationError in all three input forms (it verified successfully on the current tree), and a message that embeds the pinned certificate itself still verifies. The full universal unittest suite passes under the addr/ub sanitizer build.

Tests: CI tested

---

Pull Request resolved: #1353
commit_hash:7edf98bd3adb6418dc5d469651cc61c6b6148752
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants