[openssl-commits] [openssl] OpenSSL_1_0_1-stable update

Rich Salz rsalz at openssl.org
Sat Jan 10 21:03:15 UTC 2015


The branch OpenSSL_1_0_1-stable has been updated
       via  8fb2c9922a9c598fb34369a1f9f3cacb3a394eec (commit)
      from  a97c208c5ad7e7e339eb4683819718100cd92b29 (commit)


- Log -----------------------------------------------------------------
commit 8fb2c9922a9c598fb34369a1f9f3cacb3a394eec
Author: Dr. Stephen Henson <steve at openssl.org>
Date:   Tue Jan 6 15:29:28 2015 -0500

    RT3662: Allow leading . in nameConstraints
    
    Change by SteveH from original by John Denker (in the RT)
    
    Reviewed-by: Rich Salz <rsalz at openssl.org>
    (cherry picked from commit 77ff1f3b8bfaa348956c5096a2b829f2e767b4f1)

-----------------------------------------------------------------------

Summary of changes:
 crypto/x509v3/v3_ncons.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/crypto/x509v3/v3_ncons.c b/crypto/x509v3/v3_ncons.c
index a01dc64..3b0f1bd 100644
--- a/crypto/x509v3/v3_ncons.c
+++ b/crypto/x509v3/v3_ncons.c
@@ -401,7 +401,7 @@ static int nc_dns(ASN1_IA5STRING *dns, ASN1_IA5STRING *base)
 	if (dns->length > base->length)
 		{
 		dnsptr += dns->length - base->length;
-		if (dnsptr[-1] != '.')
+		if (*baseptr != '.' && dnsptr[-1] != '.')
 			return X509_V_ERR_PERMITTED_VIOLATION;
 		}
 


More information about the openssl-commits mailing list