diff options
author | Alexander Kanavin <alexander.kanavin@linux.intel.com> | 2018-02-01 20:01:54 +0200 |
---|---|---|
committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2018-02-19 23:53:34 +0000 |
commit | 932ecd6def4b84ac23bebe6c08c214d112028a1f (patch) | |
tree | 3410f4b2e8e44af3fa55c3f26e6692dd68bbdc8b /meta/recipes-connectivity/openssl/openssl-1.0.2n/debian1.0.2/block_digicert_malaysia.patch | |
parent | 5dc6fd13c53bf69fb9ce7c0243e6ea3dd700596d (diff) | |
download | poky-932ecd6def4b84ac23bebe6c08c214d112028a1f.tar.gz |
openssl: update to 1.0.2n
Drop upstreamed 0001-aes-armv4-bsaes-armv7-sha256-armv4-.pl-make-it-work-.patch
Rebase a couple more patches (via devtool upgrade).
(From OE-Core rev: a69526f9cd7682d8a8ff49fd8101b46616e3c05f)
Signed-off-by: Alexander Kanavin <alexander.kanavin@linux.intel.com>
Signed-off-by: Ross Burton <ross.burton@intel.com>
(cherry picked from commit 8a79b8619ce797d5395989e7bb804bc2accfbb14)
Signed-off-by: Armin Kuster <akuster808@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/recipes-connectivity/openssl/openssl-1.0.2n/debian1.0.2/block_digicert_malaysia.patch')
-rw-r--r-- | meta/recipes-connectivity/openssl/openssl-1.0.2n/debian1.0.2/block_digicert_malaysia.patch | 29 |
1 files changed, 29 insertions, 0 deletions
diff --git a/meta/recipes-connectivity/openssl/openssl-1.0.2n/debian1.0.2/block_digicert_malaysia.patch b/meta/recipes-connectivity/openssl/openssl-1.0.2n/debian1.0.2/block_digicert_malaysia.patch new file mode 100644 index 0000000000..c43bcd1c77 --- /dev/null +++ b/meta/recipes-connectivity/openssl/openssl-1.0.2n/debian1.0.2/block_digicert_malaysia.patch | |||
@@ -0,0 +1,29 @@ | |||
1 | From: Raphael Geissert <geissert@debian.org> | ||
2 | Description: make X509_verify_cert indicate that any certificate whose | ||
3 | name contains "Digicert Sdn. Bhd." (from Malaysia) is revoked. | ||
4 | Forwarded: not-needed | ||
5 | Origin: vendor | ||
6 | Last-Update: 2011-11-05 | ||
7 | |||
8 | Upstream-Status: Backport [debian] | ||
9 | |||
10 | |||
11 | Index: openssl-1.0.2~beta1/crypto/x509/x509_vfy.c | ||
12 | =================================================================== | ||
13 | --- openssl-1.0.2~beta1.orig/crypto/x509/x509_vfy.c 2014-02-25 00:16:12.488028844 +0100 | ||
14 | +++ openssl-1.0.2~beta1/crypto/x509/x509_vfy.c 2014-02-25 00:16:12.484028929 +0100 | ||
15 | @@ -964,10 +964,11 @@ | ||
16 | for (i = sk_X509_num(ctx->chain) - 1; i >= 0; i--) | ||
17 | { | ||
18 | x = sk_X509_value(ctx->chain, i); | ||
19 | - /* Mark DigiNotar certificates as revoked, no matter | ||
20 | - * where in the chain they are. | ||
21 | + /* Mark certificates containing the following names as | ||
22 | + * revoked, no matter where in the chain they are. | ||
23 | */ | ||
24 | - if (x->name && strstr(x->name, "DigiNotar")) | ||
25 | + if (x->name && (strstr(x->name, "DigiNotar") || | ||
26 | + strstr(x->name, "Digicert Sdn. Bhd."))) | ||
27 | { | ||
28 | ctx->error = X509_V_ERR_CERT_REVOKED; | ||
29 | ctx->error_depth = i; | ||