diff options
author | Michael Brown <mcb30@ipxe.org> | 2024-02-13 16:27:31 +0000 |
---|---|---|
committer | Michael Brown <mcb30@ipxe.org> | 2024-02-14 16:40:05 +0000 |
commit | 3e721e0c0836588b64deb6e1c1befd08f0f02e71 (patch) | |
tree | 417c4347622771d4fb5183cf292a69e621826519 /src/tests/x509_test.c | |
parent | e10dfe5dc7a5985333c85d6b196196b5cce9303a (diff) | |
download | ipxe-3e721e0c0836588b64deb6e1c1befd08f0f02e71.tar.gz |
[crypto] Add x509_truncate() to truncate a certificate chain
Downloading a cross-signed certificate chain to partially replace
(rather than simply extend) an existing chain will require the ability
to discard all certificates after a specified link in the chain.
Extract the relevant logic from x509_free_chain() and expose it
separately as x509_truncate().
Signed-off-by: Michael Brown <mcb30@ipxe.org>
Diffstat (limited to 'src/tests/x509_test.c')
-rw-r--r-- | src/tests/x509_test.c | 13 |
1 files changed, 13 insertions, 0 deletions
diff --git a/src/tests/x509_test.c b/src/tests/x509_test.c index b6cba575c..bc9032041 100644 --- a/src/tests/x509_test.c +++ b/src/tests/x509_test.c @@ -984,6 +984,7 @@ static void x509_validate_chain_fail_okx ( struct x509_test_chain *chn, * */ static void x509_test_exec ( void ) { + struct x509_link *link; /* Parse all certificates */ x509_certificate_ok ( &root_crt ); @@ -1089,6 +1090,18 @@ static void x509_test_exec ( void ) { x509_validate_chain_fail_ok ( &useless_chain, test_ca_expired, &empty_store, &test_root ); + /* Check chain truncation */ + link = list_last_entry ( &server_chain.chain->links, + struct x509_link, list ); + ok ( link->cert == root_crt.cert ); + link = list_prev_entry ( link, &server_chain.chain->links, list ); + ok ( link->cert == intermediate_crt.cert ); + x509_validate_chain_ok ( &server_chain, test_time, + &empty_store, &test_root ); + x509_truncate ( server_chain.chain, link ); + x509_validate_chain_fail_ok ( &server_chain, test_time, + &empty_store, &test_root ); + /* Sanity check */ assert ( list_empty ( &empty_store.links ) ); |