diff options
author | Petr Mikhalicin <pmikhalicin@rutoken.ru> | 2023-04-19 14:43:02 +0300 |
---|---|---|
committer | Tomas Mraz <tomas@openssl.org> | 2023-04-21 10:22:16 +0200 |
commit | 38ef6b018ce440a10bccfe621f51481e25790449 (patch) | |
tree | 1469b4cee1c1b106cd06153ca1fa90916b96bc0d | |
parent | 02ac9c9420275868472f33b01def01218742b8bb (diff) | |
download | openssl-new-38ef6b018ce440a10bccfe621f51481e25790449.tar.gz |
Fix checking return code of EVP_PKEY_get_int_param at check_curve
According to docs, EVP_PKEY_get_int_param should return 1 on Success, and
0 on Failure. So, fix checking of this return value at check_curve
CLA: trivial
Reviewed-by: Todd Short <todd.short@me.com>
Reviewed-by: Tomas Mraz <tomas@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/20770)
(cherry picked from commit 4e5f3d691343a691ddae739c51f7ae71e9893c98)
-rw-r--r-- | crypto/x509/x509_vfy.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/crypto/x509/x509_vfy.c b/crypto/x509/x509_vfy.c index a0282c3ef1..b6e9ee2c45 100644 --- a/crypto/x509/x509_vfy.c +++ b/crypto/x509/x509_vfy.c @@ -3421,7 +3421,7 @@ static int check_curve(X509 *cert) ret = EVP_PKEY_get_int_param(pkey, OSSL_PKEY_PARAM_EC_DECODED_FROM_EXPLICIT_PARAMS, &val); - return ret < 0 ? ret : !val; + return ret == 1 ? !val : -1; } return 1; |