Compare commits

...
Sign in to create a new pull request.

5 commits

Author SHA1 Message Date
Simon Pichugin
650a8431b9 Rebase to version 2.6.14
Resolves: rhbz#2520130
2026-08-19 23:08:41 -07:00
Jitka Plesnikova
58b2fb08f3 Perl 5.44 rebuild 2026-07-22 18:05:23 +02:00
Fedora Release Engineering
49f6d140b4 Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild 2026-07-16 10:28:24 +00:00
Simon Pichugin
a60cf65fd1 Fix build against OpenSSL 4
Bump version 2.6.13-2
2026-05-06 20:14:43 -07:00
Simon Pichugin
28101bc22f Rebase to version 2.6.13
Resolves: rhbz#2445848
2026-03-11 21:42:24 -07:00
4 changed files with 179 additions and 3 deletions

2
.gitignore vendored
View file

@ -42,3 +42,5 @@
/openldap-2.6.8.tgz
/openldap-2.6.9.tgz
/openldap-2.6.10.tgz
/openldap-2.6.13.tgz
/openldap-2.6.14.tgz

View file

@ -0,0 +1,158 @@
From 8db14ac862bd9730851a280007a899c113b7958d Mon Sep 17 00:00:00 2001
From: Howard Chu <hyc@openldap.org>
Date: Tue, 28 Apr 2026 16:49:32 +0100
Subject: [PATCH] ITS#10498 libldap: fix for OpenSSL 4 compatibility
---
libraries/libldap/tls_o.c | 53 ++++++++++++++++++---------------
servers/slapd/overlays/autoca.c | 7 ++++-
2 files changed, 35 insertions(+), 25 deletions(-)
diff --git a/libraries/libldap/tls_o.c b/libraries/libldap/tls_o.c
index cad42f8333..8d247e12c1 100644
--- a/libraries/libldap/tls_o.c
+++ b/libraries/libldap/tls_o.c
@@ -194,8 +194,8 @@ tlso_ca_list( char * bundle, char * dir, X509 *cert )
ldap_charray_free( dirs );
}
if ( cert ) {
- X509_NAME *xn = X509_get_subject_name( cert );
- xn = X509_NAME_dup( xn );
+ const X509_NAME *cxn = X509_get_subject_name( cert );
+ X509_NAME *xn = X509_NAME_dup( cxn );
if ( !ca_list )
ca_list = sk_X509_NAME_new_null();
if ( xn && ca_list )
@@ -751,7 +751,7 @@ tlso_session_my_dn( tls_session *sess, struct berval *der_dn )
{
tlso_session *s = (tlso_session *)sess;
X509 *x;
- X509_NAME *xn;
+ const X509_NAME *xn;
x = SSL_get_certificate( s );
@@ -788,7 +788,7 @@ tlso_session_peer_dn( tls_session *sess, struct berval *der_dn )
{
tlso_session *s = (tlso_session *)sess;
X509 *x = tlso_get_cert( s );
- X509_NAME *xn;
+ const X509_NAME *xn;
if ( !x )
return LDAP_INVALID_CREDENTIALS;
@@ -864,7 +864,7 @@ tlso_session_chkhost( LDAP *ld, tls_session *sess, const char *name_in )
X509_EXTENSION *ex;
STACK_OF(GENERAL_NAME) *alt;
- ex = X509_get_ext(x, i);
+ ex = (X509_EXTENSION *)X509_get_ext(x, i);
alt = X509V3_EXT_d2i(ex);
if (alt) {
int n, len2 = 0;
@@ -967,10 +967,12 @@ tlso_session_chkhost( LDAP *ld, tls_session *sess, const char *name_in )
}
if (ret != LDAP_SUCCESS) {
- X509_NAME *xn;
- X509_NAME_ENTRY *ne;
+ const X509_NAME *xn;
+ const X509_NAME_ENTRY *ne;
ASN1_OBJECT *obj;
- ASN1_STRING *cn = NULL;
+ const ASN1_STRING *cn = NULL;
+ char *cnstr;
+ int cnlen;
int navas;
/* find the last CN */
@@ -998,22 +1000,25 @@ no_cn:
}
ld->ld_error = LDAP_STRDUP(
_("TLS: unable to get CN from peer certificate"));
+ } else {
+ cnlen = ASN1_STRING_length( cn );
+ cnstr = (char *)ASN1_STRING_get0_data( cn );
+ if ( cnlen == nlen &&
+ strncasecmp( name, (char *) cnstr, nlen ) == 0 ) {
+ ret = LDAP_SUCCESS;
- } else if ( cn->length == nlen &&
- strncasecmp( name, (char *) cn->data, nlen ) == 0 ) {
- ret = LDAP_SUCCESS;
-
- } else if (( cn->data[0] == '*' ) && ( cn->data[1] == '.' )) {
- char *domain = strchr(name, '.');
- if( domain ) {
- int dlen;
+ } else if (( cnstr[0] == '*' ) && ( cnstr[1] == '.' )) {
+ char *domain = strchr(name, '.');
+ if( domain ) {
+ int dlen;
- dlen = nlen - (domain-name);
+ dlen = nlen - (domain-name);
- /* Is this a wildcard match? */
- if ((dlen == cn->length-1) &&
- !strncasecmp(domain, (char *) &cn->data[1], dlen)) {
- ret = LDAP_SUCCESS;
+ /* Is this a wildcard match? */
+ if ((dlen == cnlen-1) &&
+ !strncasecmp(domain, cnstr+1, dlen)) {
+ ret = LDAP_SUCCESS;
+ }
}
}
}
@@ -1021,7 +1026,7 @@ no_cn:
if( ret == LDAP_LOCAL_ERROR ) {
Debug3( LDAP_DEBUG_ANY, "TLS: hostname (%s) does not match "
"common name in certificate (%.*s).\n",
- name, cn->length, cn->data );
+ name, cnlen, cnstr );
ret = LDAP_CONNECT_ERROR;
if ( ld->ld_error ) {
LDAP_FREE( ld->ld_error );
@@ -1561,8 +1566,8 @@ tlso_verify_cb( int ok, X509_STORE_CTX *ctx )
X509 *cert;
int errnum;
int errdepth;
- X509_NAME *subject;
- X509_NAME *issuer;
+ const X509_NAME *subject;
+ const X509_NAME *issuer;
char *sname;
char *iname;
char *certerr = NULL;
diff --git a/servers/slapd/overlays/autoca.c b/servers/slapd/overlays/autoca.c
index 43761655d2..da978c3233 100644
--- a/servers/slapd/overlays/autoca.c
+++ b/servers/slapd/overlays/autoca.c
@@ -44,9 +44,13 @@
#if OPENSSL_VERSION_NUMBER >= 0x10100000
#include <openssl/rsa.h>
+#ifndef X509_get_notBefore
#define X509_get_notBefore(x) X509_getm_notBefore(x)
+#endif
+#ifndef X509_get_notAfter
#define X509_get_notAfter(x) X509_getm_notAfter(x)
#endif
+#endif
#if OPENSSL_VERSION_MAJOR >= 3
#define BN_pseudo_rand(bn, bits, top, bottom) BN_rand(bn, bits, top, bottom)
@@ -272,7 +276,8 @@ typedef struct genargs {
static int autoca_gencert( Operation *op, genargs *args )
{
- X509_NAME *subj_name, *issuer_name;
+ X509_NAME *subj_name;
+ const X509_NAME *issuer_name;
X509 *subj_cert;
struct berval derdn;
unsigned char *pp;
--
2.52.0

View file

@ -19,8 +19,8 @@
%global __brp_remove_la_files %nil
Name: openldap
Version: 2.6.10
Release: 7%{?dist}
Version: 2.6.14
Release: 1%{?dist}
Summary: LDAP support libraries
License: OLDAP-2.8
URL: http://www.openldap.org/
@ -565,6 +565,22 @@ exit 0
%endif
%changelog
* Thu Aug 20 2026 Simon Pichugin <spichugi@redhat.com> - 2.6.14-1
- Rebase to version 2.6.14
* Wed Jul 22 2026 Jitka Plesnikova <jplesnik@redhat.com> - 2.6.13-4
- Perl 5.44 rebuild
* Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 2.6.13-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Thu May 07 2026 Simon Pichugin <spichugi@redhat.com> - 2.6.13-2
- Fix build against OpenSSL 4
- Bump version 2.6.13-2
* Thu Mar 12 2026 Simon Pichugin <spichugi@redhat.com> - 2.6.13-1
- Rebase to version 2.6.13 (rhbz#2445848)
* Fri Jan 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 2.6.10-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild

View file

@ -1,2 +1,2 @@
SHA512 (openldap-ppolicy-check-password-1.1.tar.gz) = a92854d7438cb95fac361da80a49d084d502155e8ce0ad2ea679db9529bbe0182aa4354e6139793c775e496349375d8f017678941d23315ff1c20fefc9573cdc
SHA512 (openldap-2.6.10.tgz) = 18129ad9a385457941e3203de5f130fe2571701abf24592c5beffb01361aae3182c196b2cd48ffeecb792b9b0e5f82c8d92445a7ec63819084757bdedba63b20
SHA512 (openldap-2.6.14.tgz) = f1e25806905d729fa41e3828c257327a39abc34ed095a308a66dc49c1e3a0328df3f2db03e3bed26a50309fdfdac45d67f2761ba0bfd60c8a4d50a449869547a