From: Beat Bolli Date: Mon, 07 Sep 2026 21:12:10 GMT Subject: [PATCH 3/3] imap-send: only check the CN if no SAN DNS names are present Message-ID: <20260907211210.2621693-4-dev+git@drbeat.li> In-Reply-To: <20260907211210.2621693-1-dev+git@drbeat.li> Checking the certificate subject's common name may only be done if the subjectAltNames extension contains no DNS entries. If no SAN DNS name matches, there's no match. Per RFC 6125 section 6.4.4[1]: As noted, a client MUST NOT seek a match for a reference identifier of CN-ID if the presented identifiers include a DNS-ID, SRV-ID, URI-ID, or any application-specific identifier types supported by the client. This change was inspired by a similar commit in the HAProxy project[2]. [1]: https://datatracker.ietf.org/doc/html/rfc6125#section-6.4.4 [2]: https://github.com/haproxy/haproxy/commit/75129aaacb7a7b172f4e5334db71d6c1c50a3dbf Signed-off-by: Beat Bolli --- imap-send.c | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/imap-send.c b/imap-send.c index 9a807cdde8..66d3dbfaa5 100644 --- a/imap-send.c +++ b/imap-send.c @@ -256,11 +256,11 @@ static int verify_hostname(X509 *cert, const char *hostname) #endif const X509_NAME_ENTRY *cname_entry; const ASN1_STRING *cname; - int i, found; + int i, found, has_san_dns; STACK_OF(GENERAL_NAME) *subj_alt_names; /* try the DNS subjectAltNames */ - found = 0; + found = has_san_dns = 0; if ((subj_alt_names = X509_get_ext_d2i(cert, NID_subject_alt_name, NULL, NULL))) { int num_subj_alt_names = sk_GENERAL_NAME_num(subj_alt_names); for (i = 0; !found && i < num_subj_alt_names; i++) { @@ -268,13 +268,18 @@ static int verify_hostname(X509 *cert, const char *hostname) GENERAL_NAME *subj_alt_name = sk_GENERAL_NAME_value(subj_alt_names, i); ASN1_STRING *subj_alt_str = GENERAL_NAME_get0_value(subj_alt_name, &ntype); - if (ntype == GEN_DNS && host_matches(hostname, subj_alt_str)) - found = 1; + if (ntype == GEN_DNS) { + has_san_dns = 1; + if (host_matches(hostname, subj_alt_str)) + found = 1; + } } sk_GENERAL_NAME_pop_free(subj_alt_names, GENERAL_NAME_free); } if (found) return 0; + if (has_san_dns) + return error("none of the subjectAltNames matches hostname '%s'", hostname); /* try the common name */ if (!(subj = X509_get_subject_name(cert))) -- 2.53.0