diff options
author | djm@openbsd.org <djm@openbsd.org> | 2017-09-01 05:53:56 +0000 |
---|---|---|
committer | Damien Miller <djm@mindrot.org> | 2017-09-04 09:38:57 +1000 |
commit | b828605d51f57851316d7ba402b4ae06cf37c55d (patch) | |
tree | cec2c9c32c860e87c7a643aea1abd6c587dcd5de /dns.c | |
parent | 8042bad97e2789a50e8f742c3bcd665ebf0add32 (diff) |
upstream commit
identify the case where SSHFP records are missing but
other DNS RR types are present and display a more useful error message for
this case; patch by Thordur Bjornsson; bz#2501; ok dtucker@
Upstream-ID: 8f7a5a8344f684823d8317a9708b63e75be2c244
Diffstat (limited to 'dns.c')
-rw-r--r-- | dns.c | 14 |
1 files changed, 8 insertions, 6 deletions
@@ -1,4 +1,4 @@ | |||
1 | /* $OpenBSD: dns.c,v 1.35 2015/08/20 22:32:42 deraadt Exp $ */ | 1 | /* $OpenBSD: dns.c,v 1.36 2017/09/01 05:53:56 djm Exp $ */ |
2 | 2 | ||
3 | /* | 3 | /* |
4 | * Copyright (c) 2003 Wesley Griffin. All rights reserved. | 4 | * Copyright (c) 2003 Wesley Griffin. All rights reserved. |
@@ -294,17 +294,19 @@ verify_host_key_dns(const char *hostname, struct sockaddr *address, | |||
294 | free(dnskey_digest); | 294 | free(dnskey_digest); |
295 | } | 295 | } |
296 | 296 | ||
297 | free(hostkey_digest); /* from sshkey_fingerprint_raw() */ | 297 | if (*flags & DNS_VERIFY_FOUND) { |
298 | freerrset(fingerprints); | ||
299 | |||
300 | if (*flags & DNS_VERIFY_FOUND) | ||
301 | if (*flags & DNS_VERIFY_MATCH) | 298 | if (*flags & DNS_VERIFY_MATCH) |
302 | debug("matching host key fingerprint found in DNS"); | 299 | debug("matching host key fingerprint found in DNS"); |
300 | else if (counter == fingerprints->rri_nrdatas) | ||
301 | *flags |= DNS_VERIFY_MISSING; | ||
303 | else | 302 | else |
304 | debug("mismatching host key fingerprint found in DNS"); | 303 | debug("mismatching host key fingerprint found in DNS"); |
305 | else | 304 | } else |
306 | debug("no host key fingerprint found in DNS"); | 305 | debug("no host key fingerprint found in DNS"); |
307 | 306 | ||
307 | free(hostkey_digest); /* from sshkey_fingerprint_raw() */ | ||
308 | freerrset(fingerprints); | ||
309 | |||
308 | return 0; | 310 | return 0; |
309 | } | 311 | } |
310 | 312 | ||