Free the certificate after checking in checkCertName (#17558) [backport:1.2]
* Fix small leak in checkCertName * Size is not needed either * Free the certificate after checking
This commit is contained in:
parent
e5be216ccb
commit
b36182b0a4
2 changed files with 6 additions and 3 deletions
|
|
@ -770,10 +770,11 @@ when defineSsl:
|
||||||
raiseSSLError("No SSL certificate found.")
|
raiseSSLError("No SSL certificate found.")
|
||||||
|
|
||||||
const X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT = 0x1.cuint
|
const X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT = 0x1.cuint
|
||||||
const size = 1024
|
# https://www.openssl.org/docs/man1.1.1/man3/X509_check_host.html
|
||||||
var peername: string = newString(size)
|
|
||||||
let match = certificate.X509_check_host(hostname.cstring, hostname.len.cint,
|
let match = certificate.X509_check_host(hostname.cstring, hostname.len.cint,
|
||||||
X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT, peername)
|
X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT, nil)
|
||||||
|
# https://www.openssl.org/docs/man1.1.1/man3/SSL_get_peer_certificate.html
|
||||||
|
X509_free(certificate)
|
||||||
if match != 1:
|
if match != 1:
|
||||||
raiseSSLError("SSL Certificate check failed.")
|
raiseSSLError("SSL Certificate check failed.")
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -809,6 +809,8 @@ when not defined(nimDisableCertificateValidation) and not defined(windows):
|
||||||
|
|
||||||
proc X509_check_host*(cert: PX509, name: cstring, namelen: cint, flags:cuint, peername: cstring): cint {.cdecl, dynlib: DLLSSLName, importc.}
|
proc X509_check_host*(cert: PX509, name: cstring, namelen: cint, flags:cuint, peername: cstring): cint {.cdecl, dynlib: DLLSSLName, importc.}
|
||||||
|
|
||||||
|
proc X509_free*(cert: PX509) {.cdecl, dynlib: DLLSSLName, importc.}
|
||||||
|
|
||||||
# Certificates store
|
# Certificates store
|
||||||
|
|
||||||
type PX509_STORE* = SslPtr
|
type PX509_STORE* = SslPtr
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue