Skip to content

Commit 027ea51

Browse files
committed
crypto: preserve system CA certificate filtering
Keep the existing SSL client policy and explicitly disable network access. This avoids AIA and revocation requests without changing which certificates pass the fallback evaluation. Assisted-by: AI coding assistant Signed-off-by: Christof Marti <chrmarti@microsoft.com>
1 parent a5c25cf commit 027ea51

1 file changed

Lines changed: 6 additions & 5 deletions

File tree

‎src/crypto/crypto_context.cc‎

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -450,17 +450,18 @@ bool IsCertificateTrustValid(SecCertificateRef ref) {
450450
CFArrayCreateMutable(nullptr, 1, &kCFTypeArrayCallBacks);
451451
CFArraySetValueAtIndex(subj_certs, 0, ref);
452452

453-
// Enumerating trust anchors must not constrain them to a particular
454-
// application policy. The actual TLS handshake applies the appropriate EKU
455-
// checks when validating the peer certificate. Basic X.509 policy also
456-
// disables network access, avoiding AIA and revocation requests during
453+
// Use the SSL client policy to preserve the existing certificate filtering,
454+
// but disable network access to avoid AIA and revocation requests during
457455
// certificate enumeration.
458-
SecPolicyRef policy = SecPolicyCreateBasicX509();
456+
SecPolicyRef policy = SecPolicyCreateSSL(false, nullptr);
459457
OSStatus ortn =
460458
SecTrustCreateWithCertificates(subj_certs, policy, &sec_trust);
461459
bool result = false;
462460
if (ortn) {
463461
/* should never happen */
462+
} else if (SecTrustSetNetworkFetchAllowed(sec_trust, false) !=
463+
errSecSuccess) {
464+
/* should never happen */
464465
} else {
465466
result = SecTrustEvaluateWithError(sec_trust, nullptr);
466467
}

0 commit comments

Comments
 (0)