From: Daniel Gustafsson Date: Wed, 29 Jul 2026 19:14:18 +0000 (+0200) Subject: ssl: Replace deprecated API to get commonName X-Git-Url: http://git.ipfire.org/gitweb/?a=commitdiff_plain;h=54dee94e6a71817877dfdeb2c2c811330e58e754;p=thirdparty%2Fpostgresql.git ssl: Replace deprecated API to get commonName X509_NAME_get_text_by_NID was deprecated in OpenSSL 4.0.0, and could be removed in a future version of OpenSSL. The replacement APIs are available in all versions of OpenSSL and LibreSSL that we support so we can easily change to make the code future proof. The reason for the deprecation is that X509_NAME_get_text_by_NID can only grab the first entry in a list, and doesn't handle multibyte strings well. The fix is to get the index of the name entry with X509_NAME_get_index_by_NID and use X509_NAME_get_entry to extract the data. Author: Daniel Gustafsson Reviewed-by: Tristan Partin Reviewed-by: Andreas Karlsson Reviewed-by: Yilin Zhang Discussion: https://postgr.es/m/68B9881D-DAA8-467D-A251-C96E98E57BA0@yesql.se --- diff --git a/src/backend/libpq/be-secure-openssl.c b/src/backend/libpq/be-secure-openssl.c index 5e036cc60d2..71e20e058eb 100644 --- a/src/backend/libpq/be-secure-openssl.c +++ b/src/backend/libpq/be-secure-openssl.c @@ -1083,22 +1083,24 @@ aloop: char *peer_dn; BIO *bio = NULL; BUF_MEM *bio_buf = NULL; + int index; - len = X509_NAME_get_text_by_NID(unconstify(X509_NAME *, x509name), NID_commonName, NULL, 0); - if (len != -1) + index = X509_NAME_get_index_by_NID(unconstify(X509_NAME *, x509name), NID_commonName, -1); + if (index >= 0) { + const X509_NAME_ENTRY *entry; + const ASN1_STRING *peer_cn_asn1; + const unsigned char *peer_cn_internal; char *peer_cn; + entry = X509_NAME_get_entry(unconstify(X509_NAME *, x509name), index); + peer_cn_asn1 = X509_NAME_ENTRY_get_data(entry); + len = ASN1_STRING_length(peer_cn_asn1); + peer_cn_internal = ASN1_STRING_get0_data(peer_cn_asn1); + peer_cn = MemoryContextAlloc(TopMemoryContext, len + 1); - r = X509_NAME_get_text_by_NID(unconstify(X509_NAME *, x509name), NID_commonName, peer_cn, - len + 1); + memcpy(peer_cn, peer_cn_internal, len); peer_cn[len] = '\0'; - if (r != len) - { - /* shouldn't happen */ - pfree(peer_cn); - return -1; - } /* * Reject embedded NULLs in certificate common name to prevent