Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: TLS server certificate_sha_1 calculated incorrect hash #902

Merged
merged 1 commit into from
Oct 9, 2024

Conversation

james-ctc
Copy link
Contributor

Describe your changes

certificate_sha_1() was originally used to calculate a unique value representing a certificate. For trusted_ca_keys the certificate hash needs to be over the whole certificate.

certificate_sha_1() updated to calculate the correct hash. unit tests added to check the calculated hash
python test script to print trusted_ca_keys and certificate hashes

Issue ticket number and link

Checklist before requesting a review

  • I have performed a self-review of my code
  • I have made corresponding changes to the documentation
  • I read the contribution documentation and made sure that my changes meet its requirements

certificate_sha_1() was originally used to calculate a unique value
representing a certificate. For trusted_ca_keys the certificate hash
needs to be over the whole certificate.

certificate_sha_1() updated to calculate the correct hash.
unit tests added to check the calculated hash
python test script to print trusted_ca_keys and certificate hashes

Signed-off-by: James Chapman <[email protected]>
@james-ctc james-ctc marked this pull request as ready for review October 9, 2024 09:58
Copy link
Contributor

@AssemblyJohn AssemblyJohn left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good, I have only one question. Is the hash calculated from the DER or PEM? All certs have to be converted to DER first, right?

@james-ctc
Copy link
Contributor Author

james-ctc commented Oct 9, 2024

Is the hash calculated from the DER or PEM?

The hash is calculated of the full DER encoding of the certificate.

@james-ctc james-ctc merged commit b4f7d83 into main Oct 9, 2024
9 of 10 checks passed
@SebaLukas SebaLukas deleted the fix/trusted-ca-keys-cert-hash branch October 9, 2024 11:40
hikinggrass pushed a commit that referenced this pull request Oct 14, 2024
certificate_sha_1() was originally used to calculate a unique value
representing a certificate. For trusted_ca_keys the certificate hash
needs to be over the whole certificate.

certificate_sha_1() updated to calculate the correct hash.
unit tests added to check the calculated hash
python test script to print trusted_ca_keys and certificate hashes

Signed-off-by: James Chapman <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants