Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions modules/md/md_crypt.c
Original file line number Diff line number Diff line change
Expand Up @@ -1257,13 +1257,25 @@ int md_certs_are_equal(const md_cert_t *a, const md_cert_t *b)

int md_cert_is_valid_now(const md_cert_t *cert)
{
#if OPENSSL_VERSION_NUMBER >= 0x40000000L
return X509_check_certificate_times(NULL, cert->x509, NULL) == 1;
#else
return ((X509_cmp_current_time(X509_get_notBefore(cert->x509)) < 0)
&& (X509_cmp_current_time(X509_get_notAfter(cert->x509)) > 0));
#endif
}

int md_cert_has_expired(const md_cert_t *cert)
{
#if OPENSSL_VERSION_NUMBER >= 0x40000000L
/* Report expiry only (not a not-yet-valid notBefore), matching the
* legacy notAfter-only check below. */
int error = 0;
X509_check_certificate_times(NULL, cert->x509, &error);
return error == X509_V_ERR_CERT_HAS_EXPIRED;
#else
return (X509_cmp_current_time(X509_get_notAfter(cert->x509)) <= 0);
#endif
}

apr_time_t md_cert_get_not_after(const md_cert_t *cert)
Expand Down
18 changes: 13 additions & 5 deletions modules/ssl/ssl_engine_io.c
Original file line number Diff line number Diff line change
Expand Up @@ -1161,6 +1161,18 @@ static apr_status_t ssl_io_filter_cleanup(void *data)
return APR_SUCCESS;
}

/* Return non-zero if the certificate is not temporally valid at the
* current time, i.e. it is expired or not yet valid. */
static int cert_time_invalid(const X509 *cert)
{
#if OPENSSL_VERSION_NUMBER >= 0x40000000L
return X509_check_certificate_times(NULL, cert, NULL) != 1;
#else
return X509_cmp_current_time(X509_get_notBefore(cert)) >= 0
|| X509_cmp_current_time(X509_get_notAfter(cert)) <= 0;
#endif
}

/*
* The hook is NOT registered with ap_hook_process_connection. Instead, it is
* called manually from the churn () before it tries to read any data.
Expand Down Expand Up @@ -1294,11 +1306,7 @@ static apr_status_t ssl_io_filter_handshake(ssl_filter_ctx_t *filter_ctx)
cert = SSL_get_peer_certificate(filter_ctx->pssl);

if (dc->proxy->ssl_check_peer_expire != FALSE) {
if (!cert
|| (X509_cmp_current_time(
X509_get_notBefore(cert)) >= 0)
|| (X509_cmp_current_time(
X509_get_notAfter(cert)) <= 0)) {
if (!cert || cert_time_invalid(cert)) {
proxy_ssl_check_peer_ok = FALSE;
ap_log_cerror(APLOG_MARK, APLOG_INFO, 0, c, APLOGNO(02004)
"SSL Proxy: Peer certificate is expired");
Expand Down
2 changes: 1 addition & 1 deletion modules/ssl/ssl_private.h
Original file line number Diff line number Diff line change
Expand Up @@ -84,7 +84,7 @@
#include "ap_expr.h"

/* keep first for compat API */
#ifndef OPENSSL_API_COMPAT
#if !defined(OPENSSL_API_COMPAT) && !defined(AP_DEBUG)
#define OPENSSL_API_COMPAT 0x10101000 /* for ENGINE_ API */
#endif
#include "mod_ssl_openssl.h"
Expand Down
Loading