Repository navigation
fix crypto: use only the pinned certificate in CmsVerifier - #1353
Closed
netliomax25-code wants to merge 1 commit into
Closed
netliomax25-code wants to merge 1 commit into
netliomax25-code wants to merge 1 commit into
Conversation
Member
|
LGTM |
|
Many thanks for the PR! @apolukhin is now importing your pull request into our internal upstream repository. |
|
✅ This pull request is being closed because it has been successfully merged into our internal monorepository. |
robot-piglet
pushed a commit
that referenced
this pull request
Oct 7, 2026
1. CmsVerifier hands the pinned certificate to CMS_verify as the certs stack with a null store, but ToNativeCmsFlags never sets CMS_NOINTERN, so when the SignerInfo does not match the pinned certificate OpenSSL falls back to the certificates embedded in the message itself. 2. With a null store, signer chain verification cannot succeed, so callers have to pass kNoSignerCertVerify, and in that mode CMS_verify never checks that the resolved signer is the pinned certificate. A message signed with any key whose certificate is embedded (the CMS_sign default) is accepted by a verifier pinned to an unrelated certificate, in DER, PEM and S/MIME forms. 3. Start the native flags from CMS_NOINTERN so the signer certificate is only ever resolved from the pinned certificate. Messages signed by the pinned certificate, with or without the certificate embedded, verify as before. Added two signature_test.cpp regressions: a foreign-signer message now throws VerificationError in all three input forms (it verified successfully on the current tree), and a message that embeds the pinned certificate itself still verifies. The full universal unittest suite passes under the addr/ub sanitizer build. Tests: CI tested --- Pull Request resolved: #1353 commit_hash:7edf98bd3adb6418dc5d469651cc61c6b6148752
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Added two signature_test.cpp regressions: a foreign-signer message now throws VerificationError in all three input forms (it verified successfully on the current tree), and a message that embeds the pinned certificate itself still verifies. The full universal unittest suite passes under the addr/ub sanitizer build.