Michał Trojnara
f2f33bb131
Move providers_cleanup() back
2026-02-10 19:10:00 +01:00
Michał Trojnara
202b2c2866
Separate OpenSSL and functional initialization
2026-02-10 18:37:48 +01:00
Antoni Klajn
09d3312fd9
Fixed integer overflow, integer underflow and Out-of-Bounds Read
2026-02-06 11:39:49 +01:00
Michał Trojnara
cbee1e723c
Fixed buffer overflow while extracting msg digest
...
Reported and fixed by Antoni Klajn, Opera
2026-02-02 17:37:45 +01:00
Michał Trojnara
9924f0c085
Minor style improvements
...
- Reorder checks by corresponding RFC 5280 section numbers.
- Simplify comments.
2026-01-20 23:21:33 +01:00
olszomal
feebbcd4d9
Print current CRL during certificate verification
2026-01-07 13:36:43 +01:00
olszomal
6390ae2746
Add keyUsage digitalSignature validation for signer certificate
2025-12-31 11:38:21 +01:00
Michał Trojnara
a472d7fbff
Comment returned CRL Content-Type
2025-12-22 19:26:21 +01:00
Chris Thibodeaux
27172a07ca
Patch CRL fetch failure from expected file type
...
`application/octet-stream` response types caused CRL/TSA-CRL fetch failures
2025-12-22 19:22:01 +01:00
olszomal
d77ddb9443
Disable keep-alive and remove the shutdown workaround.
...
Some RFC 3161 TSA servers (e.g. time.certum.pl) advertise
"Connection: close" but delay closing the connection,
when keep-alive was requested. The client waited for EOF and
attempted to work around this by explicitly shutting down the socket.
2025-12-19 15:11:12 +01:00
olszomal
1d72c3da8c
Improve key/cert loading logic and standardize usage file argument names
2025-09-19 17:02:21 +02:00
olszomal
d792e8d0db
Use bio_new_file() wrapper instead of BIO_new_file() for consistent file handling
2025-09-19 17:01:02 +02:00
olszomal
bbdfc1d98a
Avoid undefined behavior with BIO_get_fp by replacing BIO_new_file with fopen + BIO_new_fp
2025-09-19 17:01:02 +02:00
olszomal
5ac11e9f58
Fix -Wsign-conversion warning in x509_name_to_utf8()
2025-07-01 12:21:44 +02:00
Michał Trojnara
97ee163e31
Document script file support
2025-06-20 14:06:05 +02:00
Michał Trojnara
dfc3e46a77
Typos
2025-06-20 12:28:43 +02:00
Michał Trojnara
e81b08e02d
Fix a comment
2025-06-20 09:58:45 +02:00
Michał Trojnara
0c85d54800
Handle missing certificate names
2025-06-19 17:56:54 +02:00
Michał Trojnara
772bc22c94
Handle null return from curl_easy_init
2025-06-19 14:32:24 +02:00
Michał Trojnara
d65a2b5286
Fix various typos
2025-06-19 14:18:26 +02:00
olszomal
dd9b81281f
Support loading OpenSSL 3.0+ providers without -pkcs11module option (e.g., CNG)
2025-06-05 17:13:10 +02:00
Michał Trojnara
52bfff5756
Avoid variable reuse
2025-06-04 18:42:41 +02:00
Michał Trojnara
50c23daa4c
Code simplification
...
No functional change intended.
2025-06-03 08:20:52 +02:00
Michał Trojnara
9b7dae4572
Support loading arbitrary engines via ENGINE_by_id()
...
Use ENGINE_by_id() for any engine name that doesn't contain a dot,
assuming it's an engine ID. If the name includes a dot (e.g., a file
extension), treat it as a path to a dynamic engine module.
See #436 for discussion.
2025-06-02 20:32:26 +02:00
Michał Trojnara
62438908cb
Skip the "lib" prefix when guessing engine ID
...
Fix #436
2025-05-30 16:59:25 +02:00
olszomal
829e770250
Use _WIN32 instead of USE_WIN32 for MinGW compatibility
2025-05-27 10:17:03 +02:00
olszomal
10ca3a06ea
Suppress compiler warnings
2025-05-06 10:42:53 +02:00
olszomal
9ea7e85468
Fix engine-less builds
2025-05-06 10:42:53 +02:00
olszomal
68e8845ef1
Improve PKCS#7 verification with OpenSSL 3.5
...
Enhanced verification logic for PKCS#7 signedData structures by introducing a dedicated `verify_pkcs7_data()` function. This update addresses compatibility with older OpenSSL versions (< 3.0.5) and ensures correct handling of detached signed content using a BIO buffer.
The change enables support for PKCS#7 inner content (RFC 2315, section 7), as per OpenSSL PR#22575.
Refactored timestamp and authenticode verification functions to reduce duplication and properly manage X509_STORE and X509_CRL structures.
2025-05-01 11:21:29 +02:00
olszomal
475ea95ba3
Fix control flow and braces for engine and provider support
2025-05-01 11:21:29 +02:00
Maxim Bagryantsev
d352dcc1a5
Do not try to load engine twice
2025-04-18 10:46:20 +02:00
olszomal
4bd167a8be
Fixed directly dereferencing parameter p7, CID 1576008
2025-03-31 13:19:35 +02:00
olszomal
e7405fa839
Simplify error handling in PKCS#7 certificate loading, CID 1639170
2025-03-31 13:19:35 +02:00
olszomal
838aaaee8d
libp11 PKCS#11 provider support
2025-03-28 14:05:12 +01:00
olszomal
e8f19a6efe
Added verbose output for digest encryption algorithm and signature during verification
2024-12-31 13:53:46 +01:00
olszomal
40ce811701
Fixed conditional compilation for CURL and proxy support
2024-10-25 17:48:01 +02:00
Małgorzata Olszówka
db5b4c4dc0
Add the "-engineCtrl" option to control hardware and CNG engines ( #405 )
...
Documentation updated for CNG engine 1.1 compatibility.
2024-09-08 19:23:38 +02:00
olszomal
21133f9c3b
Added the '-blobFile' option to specify a file containing the blob content
2024-09-04 17:51:35 +02:00
olszomal
2b3228d549
Changed error output to stderr instead of stdout
2024-06-05 16:54:21 +02:00
olszomal
476168e09e
Added the "-ignore-crl" option to disable CRL online verification
2024-06-03 12:16:02 +02:00
olszomal
41b662a8fe
Checked cFolders value
2024-05-31 16:47:31 +02:00
Brad Hughes
825c9dad7c
Add '-login' option to force a login to PKCS11 engines
2024-05-22 19:06:06 +02:00
Małgorzata Olszówka
6e5bef14e9
Rewrite making test certificates ( #393 )
...
Also updates obsolete curl dependencies with zlib.
2024-05-22 18:59:53 +02:00
olszomal
aa8c8dd720
Type casting of the read() return value
2024-04-10 17:09:01 +02:00
olszomal
16c5e5aa4a
Squashed logically dead code for curl response code for openssl version 3.0.0 and later, CID 1585046
2024-04-10 17:09:01 +02:00
Michał Trojnara
ded1f7aa67
Use native HTTP client with OpenSSL 3.0 or later ( #378 )
...
Co-authored-by: olszomal <Malgorzata.Olszowka@stunnel.org >
2024-04-09 19:33:31 +02:00
Steve McIntyre
6ad2679f17
Read the password from stdin if desired
...
Use the common convention: "-" means to use stdin
Signed-off-by: Steve McIntyre <steve.mcintyre@pexip.com >
2024-03-28 21:33:01 +01:00
olszomal
4776f43f04
Improved manual
2024-03-26 18:28:02 +01:00
olszomal
0a0761746f
Fixed memory corruption
2024-03-08 16:59:34 +01:00
olszomal
f51e2a4869
Intercepted X509_V_FLAG_CHECK_SS_SIGNATURE verify error
2024-03-08 16:59:34 +01:00