git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2 1/3] imap-send: use the OpenSSL API to access the subject alternative names

From
Beat Bolli <dev+git@drbeat.li>
Date
Mar 11, 2026, 22:10 UTC
Message-ID
<20260311221027.1404476-2-dev+git@drbeat.li>
In-Reply-To
<20260311121107.1122387-1-dev+git@drbeat.li>

The OpenSSL 4.0 master branch has made the ASN1_STRING structure opaque, forbidding access to its internal fields. Use the official accessor functions instead. They have existed since OpenSSL v1.1.0.

Signed-off-by: Beat Bolli <dev+git@drbeat.li>
---
 imap-send.c | 10 +++++++---
 1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/imap-send.c b/imap-send.c
index 26dda7f328..1c934c2487 100644
--- a/imap-send.c
+++ b/imap-send.c
@@ -244,10 +244,14 @@ static int verify_hostname(X509 *cert, const char *hostname)
 	if ((subj_alt_names = X509_get_ext_d2i(cert, NID_subject_alt_name, NULL, NULL))) {
 		int num_subj_alt_names = sk_GENERAL_NAME_num(subj_alt_names);
 		for (i = 0; !found && i < num_subj_alt_names; i++) {
+			int ntype;
 			GENERAL_NAME *subj_alt_name = sk_GENERAL_NAME_value(subj_alt_names, i);
-			if (subj_alt_name->type == GEN_DNS &&
-			    strlen((const char *)subj_alt_name->d.ia5->data) == (size_t)subj_alt_name->d.ia5->length &&
-			    host_matches(hostname, (const char *)(subj_alt_name->d.ia5->data)))
+			ASN1_STRING *subj_alt_str = GENERAL_NAME_get0_value(subj_alt_name, &ntype);
+
+			if (ntype == GEN_DNS &&
+			    strlen((const char *)ASN1_STRING_get0_data(subj_alt_str)) ==
+				    ASN1_STRING_length(subj_alt_str) &&
+			    host_matches(hostname, (const char *)ASN1_STRING_get0_data(subj_alt_str)))
 				found = 1;
 		}
 		sk_GENERAL_NAME_pop_free(subj_alt_names, GENERAL_NAME_free);
-- 
2.51.0
Previous: Beat BolliNext: Beat Bolli
Message 10 of 14 in “imap-send: modernize the OpenSSL API”
  1. 0/4 imap-send: modernize the OpenSSL APIBeat Bolli, Mar 11, 2026
  2. 3/4 imap-send: remove two string length checksBeat Bolli, Mar 11, 2026
  3. Oswald BuddenhagenMar 11, 2026
  4. Beat BolliMar 11, 2026
  5. Junio C HamanoMar 11, 2026
  6. Beat BolliMar 11, 2026
  7. 4/4 imap-send: refactor function host_matches()Beat Bolli, Mar 11, 2026
  8. 2/4 imap-send: use the OpenSSL API to access the subject common nameBeat Bolli, Mar 11, 2026
  9. 1/4 imap-send: use the OpenSSL API to access the subject alternative namesBeat Bolli, Mar 11, 2026
  10. 1/3 imap-send: use the OpenSSL API to access the subject alternative namesBeat Bolli, Mar 11, 2026
  11. 0/3 imap-send: modernize the OpenSSL APIBeat Bolli, Mar 11, 2026
  12. Junio C HamanoMar 12, 2026
  13. 3/3 imap-send: move common code into function host_matches()Beat Bolli, Mar 11, 2026
  14. 2/3 imap-send: use the OpenSSL API to access the subject common nameBeat Bolli, Mar 11, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.