Skip to content

Commit 52861cb

Browse files
authored
Merge pull request #7476 from per-allansson/one-crl-to-rule-them-all
An expired CRL should not override a successful match in other CRL
2 parents 9711070 + b88803c commit 52861cb

1 file changed

Lines changed: 7 additions & 2 deletions

File tree

src/crl.c

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -392,6 +392,8 @@ static int CheckCertCRLList(WOLFSSL_CRL* crl, byte* issuerHash, byte* serial,
392392

393393
for (crle = crl->crlList; crle != NULL; crle = crle->next) {
394394
if (XMEMCMP(crle->issuerHash, issuerHash, CRL_DIGEST_SIZE) == 0) {
395+
int nextDateValid = 1;
396+
395397
WOLFSSL_MSG("Found CRL Entry on list");
396398

397399
if (crle->verified == 0) {
@@ -426,17 +428,20 @@ static int CheckCertCRLList(WOLFSSL_CRL* crl, byte* issuerHash, byte* serial,
426428
#if !defined(NO_ASN_TIME) && !defined(WOLFSSL_NO_CRL_DATE_CHECK)
427429
if (!XVALIDATE_DATE(crle->nextDate,crle->nextDateFormat, AFTER)) {
428430
WOLFSSL_MSG("CRL next date is no longer valid");
429-
ret = ASN_AFTER_DATE_E;
431+
nextDateValid = 0;
430432
}
431433
#endif
432434
}
433-
if (ret == 0) {
435+
if (nextDateValid) {
434436
foundEntry = 1;
435437
ret = FindRevokedSerial(crle->certs, serial, serialSz,
436438
serialHash, crle->totalCerts);
437439
if (ret != 0)
438440
break;
439441
}
442+
else if (foundEntry == 0) {
443+
ret = ASN_AFTER_DATE_E;
444+
}
440445
}
441446
}
442447

0 commit comments

Comments
 (0)