<html>
<head>
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<div class="moz-cite-prefix">On 10/06/2015 12:41, Thulasi Goriparthi
wrote:<br>
</div>
<blockquote
cite="mid:CAB7O4Gzb3o7wvB7FQTca777+dra_0wt7ktfY+PzmrV9jn_YOUQ@mail.gmail.com"
type="cite">
<div dir="ltr">
<div>
<div>
<div>X509_STORE_add_cert increments the reference count of
the each cert, but only by 1.<br>
</div>
</div>
</div>
</div>
</blockquote>
<tt>Sounds like there should be X509_STORE_add0_cert() and <br>
X509_STORE_add1_cert() like for other parts of the library.</tt><br>
<blockquote
cite="mid:CAB7O4Gzb3o7wvB7FQTca777+dra_0wt7ktfY+PzmrV9jn_YOUQ@mail.gmail.com"
type="cite">
<div dir="ltr">
<div>
<div>X509_STORE_free decrements the ref count by 1. So after
decrementing, if ref_count is 0, certificate will be freed.
<br>
</div>
<br>
Jakob is saying that if you want them to stay even after
X509_STORE_free, explicitly increment the ref count before
calling free using something like below.<br>
<br>
</div>
</div>
</blockquote>
<tt>Interesting! I assumed (based on the standard <br>
refcounting paradigm) that the reference count of a <br>
new object would be 1, and that some API (perhaps <br>
X509_free()) would decrement and free if it hit 0.</tt><tt><br>
</tt><br>
<blockquote
cite="mid:CAB7O4Gzb3o7wvB7FQTca777+dra_0wt7ktfY+PzmrV9jn_YOUQ@mail.gmail.com"
type="cite">
<div dir="ltr">
<div>CRYPTO_add(certificate->references, 1,
CRYPTO_LOCK_X509);<br>
<br>
</div>
</div>
</blockquote>
<tt>Is there really no proper API wrapping this?</tt><br>
<blockquote
cite="mid:CAB7O4Gzb3o7wvB7FQTca777+dra_0wt7ktfY+PzmrV9jn_YOUQ@mail.gmail.com"
type="cite">
<div dir="ltr">
<div><br>
</div>
<div>decrypt the ref count when you really want to free them and
call X509_free(certificate).<br>
<tt><br>
</tt></div>
</div>
</blockquote>
<tt>Is there really no proper API wrapping this?</tt>
<blockquote
cite="mid:CAB7O4Gzb3o7wvB7FQTca777+dra_0wt7ktfY+PzmrV9jn_YOUQ@mail.gmail.com"
type="cite">
<div class="gmail_extra"><br>
<div class="gmail_quote">On 10 June 2015 at 10:20, Nayna Jain <span
dir="ltr"><<a moz-do-not-send="true"
href="mailto:naynjain@in.ibm.com" target="_blank">naynjain@in.ibm.com</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">
<div bgcolor="#FFFFFF">
<p><font face="sans-serif" size="2">Thanks Jacob,</font><br>
<font face="sans-serif" size="2">So, does that API do
not increment reference count internally itself.</font><br>
<br>
<font face="sans-serif" size="2">I mean if I have to
explicitly do that, what is the API for that ? </font><br>
<span class="">
<br>
<font face="sans-serif" size="2">Thanks & Regards,<br>
Nayna Jain</font><br>
<br>
</span><img src="cid:part2.05060507.06000308@wisemo.com"
alt="Inactive hide details for Jakob Bohm
---06/10/2015 09:49:54 AM---On 10/06/2015 05:22, Nayna
Jain wrote: >" border="0" height="16" width="16"><font
color="#424282" face="sans-serif" size="2">Jakob Bohm
---06/10/2015 09:49:54 AM---On 10/06/2015 05:22, Nayna
Jain wrote: ></font><br>
<br>
<font color="#5F5F5F" face="sans-serif" size="1">From: </font><font
face="sans-serif" size="1">Jakob Bohm <<a
moz-do-not-send="true"
href="mailto:jb-openssl@wisemo.com" target="_blank">jb-openssl@wisemo.com</a>></font><br>
<font color="#5F5F5F" face="sans-serif" size="1">To: </font><font
face="sans-serif" size="1"><a moz-do-not-send="true"
href="mailto:openssl-users@openssl.org"
target="_blank">openssl-users@openssl.org</a></font><br>
<font color="#5F5F5F" face="sans-serif" size="1">Date: </font><font
face="sans-serif" size="1">06/10/2015 09:49 AM</font><br>
<font color="#5F5F5F" face="sans-serif" size="1">Subject:
</font><font face="sans-serif" size="1">Re:
[openssl-users] X509_STORE_free() and
X509_LOOKUP_free() also frees the X509 certificates
inside it</font><br>
<font color="#5F5F5F" face="sans-serif" size="1">Sent
by: </font><font face="sans-serif" size="1">"openssl-users"
<<a moz-do-not-send="true"
href="mailto:openssl-users-bounces@openssl.org"
target="_blank">openssl-users-bounces@openssl.org</a>></font><br>
</p>
<hr style="color:#8091a5" align="left" noshade="noshade"
size="2" width="100%">
<div>
<div class="h5"><br>
<br>
<br>
<br>
<font face="serif" size="3">On 10/06/2015 05:22, Nayna
Jain wrote:</font>
<ul style="padding-left:36pt">
<br>
<font face="sans-serif" size="2">Hi all,</font><font
face="serif" size="3"><br>
</font><font face="sans-serif" size="2"><br>
I am using X509_STORE and X509_LOOKUP to verify
the certificate and its chain.</font><font
face="serif" size="3"><br>
</font><font face="sans-serif" size="2"><br>
But at the end when I do X509_STORE_free(store)
and X509_LOOKUP_free(lookup), it is also doing
free of the X509* certificate which I added.<br>
But I don't want that, because after that when I
immediately try to access X509* certificate for
further operation, then it results in core dump</font><font
face="serif" size="3"><br>
</font><font face="sans-serif" size="2"><br>
And if I don't do X509_STORE_free() then it will
leave the memory leak.<br>
<br>
Let me know how to resolve this and if I
misunderstood something.</font>
</ul>
<br>
<tt><font size="3">X509 objects (and many other
objects in the API) are <br>
reference counted.<br>
<br>
Increment the reference count of each certificate
as <br>
you add it to the X509_STORE, this should make the
<br>
X509 object stay around after X509_STORE_free()
frees <br>
it.<br>
<br>
However there is a shortage of documentation on
the <br>
reference counting functions involved.<br>
</font></tt><br>
</div>
</div>
</div>
</blockquote>
</div>
</div>
</blockquote>
<br>
<br>
<pre class="moz-signature" cols="72">Enjoy
Jakob
--
Jakob Bohm, CIO, Partner, WiseMo A/S. <a class="moz-txt-link-freetext" href="http://www.wisemo.com">http://www.wisemo.com</a>
Transformervej 29, 2860 Søborg, Denmark. Direct +45 31 13 16 10
This public discussion message is non-binding and may contain errors.
WiseMo - Remote Service Management for PCs, Phones and Embedded </pre>
</body>
</html>