Selaa lähdekoodia

[crypto] Allow certificates to be marked as having been added explicitly

Allow certificates to be marked as having been added explicitly at run
time.  Such certificates will not be discarded via the certificate
store cache discarder.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
tags/v1.20.1
Michael Brown 7 vuotta sitten
vanhempi
commit
9a1a42f283
2 muutettua tiedostoa jossa 23 lisäystä ja 4 poistoa
  1. 19
    4
      src/crypto/certstore.c
  2. 4
    0
      src/include/ipxe/x509.h

+ 19
- 4
src/crypto/certstore.c Näytä tiedosto

@@ -152,6 +152,10 @@ void certstore_add ( struct x509_certificate *cert ) {
152 152
  */
153 153
 void certstore_del ( struct x509_certificate *cert ) {
154 154
 
155
+	/* Ignore attempts to remove permanent certificates */
156
+	if ( cert->flags & X509_FL_PERMANENT )
157
+		return;
158
+
155 159
 	/* Remove certificate from store */
156 160
 	DBGC ( &certstore, "CERTSTORE removed certificate %s\n",
157 161
 	       x509_name ( cert ) );
@@ -171,11 +175,22 @@ static unsigned int certstore_discard ( void ) {
171 175
 	 * only reference is held by the store itself.
172 176
 	 */
173 177
 	list_for_each_entry_reverse ( cert, &certstore.links, store.list ) {
174
-		if ( cert->refcnt.count == 0 ) {
175
-			certstore_del ( cert );
176
-			return 1;
177
-		}
178
+
179
+		/* Skip certificates for which another reference is held */
180
+		if ( cert->refcnt.count > 0 )
181
+			continue;
182
+
183
+		/* Skip certificates that were added at build time or
184
+		 * added explicitly at run time.
185
+		 */
186
+		if ( cert->flags & ( X509_FL_PERMANENT | X509_FL_EXPLICIT ) )
187
+			continue;
188
+
189
+		/* Discard certificate */
190
+		certstore_del ( cert );
191
+		return 1;
178 192
 	}
193
+
179 194
 	return 0;
180 195
 }
181 196
 

+ 4
- 0
src/include/ipxe/x509.h Näytä tiedosto

@@ -220,6 +220,10 @@ struct x509_certificate {
220 220
 enum x509_flags {
221 221
 	/** Certificate has been validated */
222 222
 	X509_FL_VALIDATED = 0x0001,
223
+	/** Certificate was added at build time */
224
+	X509_FL_PERMANENT = 0x0002,
225
+	/** Certificate was added explicitly at run time */
226
+	X509_FL_EXPLICIT = 0x0004,
223 227
 };
224 228
 
225 229
 /**

Loading…
Peruuta
Tallenna