vquic-tls: use correct cert name check API for wolfSSL

wolfSSL_X509_check_host checks the peer name against the alt names and
the common name.

Fixes #13487
Closes #13680
This commit is contained in:
Juliusz Sosinowicz 2024-05-16 20:16:37 +02:00 committed by Daniel Stenberg
parent 9e2bd56ec6
commit 4c46e277b2
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
2 changed files with 9 additions and 13 deletions

View file

@ -126,7 +126,6 @@
13.13 Make sure we forbid TLS 1.3 post-handshake authentication
13.14 Support the clienthello extension
13.15 Select signature algorithms
13.16 QUIC peer verification with wolfSSL
14. GnuTLS
14.2 check connection
@ -922,11 +921,6 @@
https://github.com/curl/curl/issues/12982
13.16 QUIC peer verification with wolfSSL
Peer certificate verification is missing in the QUIC (ngtcp2) implementation
using wolfSSL.
14. GnuTLS
14.2 check connection

View file

@ -324,13 +324,15 @@ CURLcode Curl_vquic_tls_verify_peer(struct curl_tls_ctx *ctx,
#elif defined(USE_WOLFSSL)
(void)data;
if(conn_config->verifyhost) {
/* TODO: this does not really verify the peer certificate.
* On TCP connection this works as it is wired into the wolfSSL
* connect() implementation and gives a special return code on
* such a fail. */
if(peer->sni &&
wolfSSL_check_domain_name(ctx->ssl, peer->sni) == SSL_FAILURE)
return CURLE_PEER_FAILED_VERIFICATION;
if(peer->sni) {
WOLFSSL_X509* cert = wolfSSL_get_peer_certificate(ctx->ssl);
if(wolfSSL_X509_check_host(cert, peer->sni, strlen(peer->sni), 0, NULL)
== WOLFSSL_FAILURE) {
result = CURLE_PEER_FAILED_VERIFICATION;
}
wolfSSL_X509_free(cert);
}
}
#endif
return result;