Thanks for patch and review. I have not tested this beyond a cursory
"stare at code" and relying on the BB and GHA test builds for testing
the client side (which do not excercise this feature, but will find
other breakage).
This was reported to us as a security bug, and we did assign a CVE ID
- but we've decided to not keep this under embargo, as it needs very
particular circumstances to have adverse effects, namely an mbedTLS
build with --x509-username-field in use, plus an adverse CA that
publishes a "bad" certificate that just so happens to match the
unintended certificate check caused by this bug.
Your patch has been applied to the master and release/2.7 branch.
commit 124ec07732bccc1fced2d8d37c71b761daf75f4f (master)
commit 08bbc4905c15ac3d72cd11f18be668ac188a8ccc (release/2.7)
Author: Max Fillinger
Date: Wed Jul 22 17:25:14 2026 +0200
Make --x509-username-field work with Mbed TLS
Signed-off-by: Max Fillinger <[email protected]>
Acked-by: Frank Lichtenheld <[email protected]>
Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1801
Message-Id: <[email protected]>
URL:
https://www.mail-archive.com/[email protected]/msg37773.html
Signed-off-by: Gert Doering <[email protected]>
--
kind regards,
Gert Doering
_______________________________________________
Openvpn-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-devel