Skip to content

output UTF-8 decoded id-on-xmppAddr SAN's

Steffen Jaeckel requested to merge jaeckel/gnutls:fix-id-on-xmppAddr into master

Checklist

  • Commits have Signed-off-by: with name/author being identical to the commit author
  • Code modified for feature
  • Test suite updated with functionality tests
  • Test suite updated with negative tests
  • Documentation updated / NEWS entry present (for non-trivial changes)
  • CI timeout is 2h or higher (see Settings/CICD/General pipelines/Timeout)

Reviewer's checklist:

  • Any issues marked for closing are addressed
  • There is a test suite reasonably covering new functionality or modifications
  • Function naming, parameters, return values, types, etc., are consistent and according to CONTRIBUTION.md
  • This feature/change has adequate documentation added
  • No obvious mistakes in the code

gnutls_x509_crt_get_subject_alt_name() makes a promise [1] "If an otherName OID is known, the data will be decoded. ... RFC 3920 id-on-xmppAddr SAN is recognized." which it didn't hold.

Before this patch the output was still in DER format, e.g. for a id-on-xmppAddr which is always UTF-8 (0x0c): 0x0c <len> <xmppAddr>

This patch fixes the issue and now it returns the decoded string.

[1] https://www.gnutls.org/manual/gnutls.html#gnutls_005fx509_005fcrt_005fget_005fsubject_005falt_005fname

Edited by Steffen Jaeckel

Merge request reports