From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED.blaine.gmane.org!not-for-mail From: Lars Ingebrigtsen Newsgroups: gmane.emacs.bugs Subject: bug#35787: 26.2; gnutls: accessing raw server certificate data Date: Tue, 09 Jul 2019 15:44:42 +0200 Message-ID: References: <87r270dj2l.fsf@mouse.gnus.org> Mime-Version: 1.0 Content-Type: text/plain Injection-Info: blaine.gmane.org; posting-host="blaine.gmane.org:195.159.176.226"; logging-data="145709"; mail-complaints-to="usenet@blaine.gmane.org" User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.0.50 (gnu/linux) Cc: 35787@debbugs.gnu.org To: Julian Scheid Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Tue Jul 09 16:51:49 2019 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([209.51.188.17]) by blaine.gmane.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.89) (envelope-from ) id 1hkrTB-000a45-15 for geb-bug-gnu-emacs@m.gmane.org; Tue, 09 Jul 2019 16:51:49 +0200 Original-Received: from localhost ([::1]:50600 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.86_2) (envelope-from ) id 1hkrEB-00040M-9t for geb-bug-gnu-emacs@m.gmane.org; Tue, 09 Jul 2019 10:36:19 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]:32806) by lists.gnu.org with esmtp (Exim 4.86_2) (envelope-from ) id 1hkrDz-000404-A3 for bug-gnu-emacs@gnu.org; Tue, 09 Jul 2019 10:36:08 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1hkrDy-0007o0-1O for bug-gnu-emacs@gnu.org; Tue, 09 Jul 2019 10:36:07 -0400 Original-Received: from debbugs.gnu.org ([209.51.188.43]:53101) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1hkrDu-0007mt-1g for bug-gnu-emacs@gnu.org; Tue, 09 Jul 2019 10:36:03 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1hkrDt-0000rC-UQ for bug-gnu-emacs@gnu.org; Tue, 09 Jul 2019 10:36:01 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Lars Ingebrigtsen Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Tue, 09 Jul 2019 14:36:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 35787 X-GNU-PR-Package: emacs Original-Received: via spool by 35787-submit@debbugs.gnu.org id=B35787.15626829363259 (code B ref 35787); Tue, 09 Jul 2019 14:36:01 +0000 Original-Received: (at 35787) by debbugs.gnu.org; 9 Jul 2019 14:35:36 +0000 Original-Received: from localhost ([127.0.0.1]:33689 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1hkrDT-0000qV-V1 for submit@debbugs.gnu.org; Tue, 09 Jul 2019 10:35:36 -0400 Original-Received: from quimby.gnus.org ([80.91.231.51]:46854) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1hkr02-0006iE-0i for 35787@debbugs.gnu.org; Tue, 09 Jul 2019 10:21:42 -0400 Original-Received: from cm-84.212.202.86.getinternet.no ([84.212.202.86] helo=stories) by quimby.gnus.org with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.89) (envelope-from ) id 1hkqQE-0005mw-KA; Tue, 09 Jul 2019 15:44:45 +0200 Face: iVBORw0KGgoAAAANSUhEUgAAADAAAAAwBAMAAAClLOS0AAAAElBMVEUUDAwoFReFOjcMBgXL a11aJiaNjLxJAAACWUlEQVQ4jW2UTZLjIAyFRdzZQ9I+ACrYkya5gErsByrc/yrzhJ2ezbBwEj7r /ymU5/8Od+rh9xBO8PZ0+BEIXz05d9yc931dE115zk6zw0nPhw+6E23llThFx8zzzZkj7j0stlpf SbTvg7uB0UK4F7pXnBcL9zBymCP3GyzqAejFKr3f3sqD4y06XwgAj2tSiXlX4cSTo+VDd4f8f1S1 z5s2zYgUCU7I6qoPgDiSzozMJNKGnCyz+jJwU0UOcwCgbICwLZAB9r5PWKw64GqriCE5qc4+DFjY FWMDyG/VNnKbSaJ3ZzsRXKZ5w+uDrSWejuBPFRjoxK0Bd4KtPoUBxABOXB1fA3pKhkGbuE3MaOKq I5jFAoeBtjU/PGr9kbFqx7AZL5gj2KC9T02W1LDnB6x5fElS1uMIgIlhgYsMSSdIZvEBP9r1BHIA f7rS+O/+1xXV8mVNZ3PDegBH922BfLN32Vp8Ar8VAMkXSSyT9QSIAVmVi8SLKMc9fYApERZX7ReR HMZpYVn5ZQHABlZibYnbwGOX8IX27XwAt3QF4K7ZfzNDcav0tjbFLzB9GmnaFCHG5lcTIRK69l1t B8xgJIsBUACcfwuPbCESf+owCxeElZseIJ51bIXctwjmkFYTpS9N+WWBzYBurVtJJnRFZY2WnCmk oTzMPs9usl3pYlBhQM8I8G69m9SOAqH2ncPOjWeK+/TwUsyi0EsCFjPnjP3csfFn5Q96NfdnH4iD hZsWoSwQ6IKVQXQs827/CweAN+ixFnwn6wI+EdX2/FFdLXX9sNV+4B5x/wKuJbN8Ljru7QAAAABJ RU5ErkJggg== In-Reply-To: (Julian Scheid's message of "Mon, 8 Jul 2019 22:20:46 -0600") X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 209.51.188.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.org gmane.emacs.bugs:162476 Archived-At: Julian Scheid writes: > So, to make this work it looks like I'd need either > > 1) the fingerprint, but using the hash function as required by the RFC, or > 2) the certificate as a binary blob. I think putting the signature itself in the process object (in addition to all the details) makes some sense, but perhaps it's wastes unnecessary memory... There's gnutls-peer-status, and that could also be amended to return the full certificate. But, again, that's also called for virtually any TLS connection. Perhaps a new function to return the actual certificate? And perhaps it should just return the entire certificate chain? Anybody got an opinion here? -- (domestic pets only, the antidote for overdose, milk.) bloggy blog: http://lars.ingebrigtsen.no