[PATCH 3/3] imap-send: only check the CN if no SAN DNS names are present
- From
Beat Bolli <dev+git@drbeat.li>
- Date
- Sep 7, 2026, 21:12 UTC
- Message-ID
- <20260907211210.2621693-4-dev+git@drbeat.li>
- In-Reply-To
- <20260907211210.2621693-1-dev+git@drbeat.li>
Checking the certificate subject's common name may only be done if the subjectAltNames extension contains no DNS entries. If no SAN DNS name matches, there's no match.
Per RFC 6125 section 6.4.4[1]:
As noted, a client MUST NOT seek a match for a reference identifier
of CN-ID if the presented identifiers include a DNS-ID, SRV-ID,
URI-ID, or any application-specific identifier types supported by the
client.This change was inspired by a similar commit in the HAProxy project[2].
[1]: https://datatracker.ietf.org/doc/html/rfc6125#section-6.4.4 [2]: https://github.com/haproxy/haproxy/commit/75129aaacb7a7b172f4e5334db71d6c1c50a3dbf
Signed-off-by: Beat Bolli <dev+git@drbeat.li> --- imap-send.c | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/imap-send.c b/imap-send.c index 9a807cdde8..66d3dbfaa5 100644 --- a/imap-send.c +++ b/imap-send.c @@ -256,11 +256,11 @@ static int verify_hostname(X509 *cert, const char *hostname) #endif const X509_NAME_ENTRY *cname_entry; const ASN1_STRING *cname; - int i, found; + int i, found, has_san_dns; STACK_OF(GENERAL_NAME) *subj_alt_names; /* try the DNS subjectAltNames */ - found = 0; + found = has_san_dns = 0; if ((subj_alt_names = X509_get_ext_d2i(cert, NID_subject_alt_name, NULL, NULL))) { int num_subj_alt_names = sk_GENERAL_NAME_num(subj_alt_names); for (i = 0; !found && i < num_subj_alt_names; i++) { @@ -268,13 +268,18 @@ static int verify_hostname(X509 *cert, const char *hostname) GENERAL_NAME *subj_alt_name = sk_GENERAL_NAME_value(subj_alt_names, i); ASN1_STRING *subj_alt_str = GENERAL_NAME_get0_value(subj_alt_name, &ntype); - if (ntype == GEN_DNS && host_matches(hostname, subj_alt_str)) - found = 1; + if (ntype == GEN_DNS) { + has_san_dns = 1; + if (host_matches(hostname, subj_alt_str)) + found = 1; + } } sk_GENERAL_NAME_pop_free(subj_alt_names, GENERAL_NAME_free); } if (found) return 0; + if (has_san_dns) + return error("none of the subjectAltNames matches hostname '%s'", hostname); /* try the common name */ if (!(subj = X509_get_subject_name(cert)))
-- 2.53.0