aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorIngela Anderton Andin <[email protected]>2016-06-08 14:29:46 +0200
committerIngela Anderton Andin <[email protected]>2016-06-09 10:38:45 +0200
commit20b3aa4dabab14ea1a653fb9f88c842edd0e2a69 (patch)
treee30b7d6bc857017d8cf189e233bee80a14cf4fca
parenta39395d4f99aff99ac57ab40a3191fa13a7371fd (diff)
downloadotp-20b3aa4dabab14ea1a653fb9f88c842edd0e2a69.tar.gz
otp-20b3aa4dabab14ea1a653fb9f88c842edd0e2a69.tar.bz2
otp-20b3aa4dabab14ea1a653fb9f88c842edd0e2a69.zip
ssl: Propagate error so that public_key crl validation process continues
correctly and determines what should happen.
-rw-r--r--lib/ssl/src/ssl_crl.erl16
1 files changed, 7 insertions, 9 deletions
diff --git a/lib/ssl/src/ssl_crl.erl b/lib/ssl/src/ssl_crl.erl
index faf5007b16..d9f21e04ac 100644
--- a/lib/ssl/src/ssl_crl.erl
+++ b/lib/ssl/src/ssl_crl.erl
@@ -39,13 +39,12 @@ trusted_cert_and_path(CRL, {SerialNumber, Issuer},{Db, DbRef} = DbHandle) ->
end;
trusted_cert_and_path(CRL, issuer_not_found, {Db, DbRef} = DbHandle) ->
- try find_issuer(CRL, DbHandle) of
- OtpCert ->
+ case find_issuer(CRL, DbHandle) of
+ {ok, OtpCert} ->
{ok, Root, Chain} = ssl_certificate:certificate_chain(OtpCert, Db, DbRef),
- {ok, Root, lists:reverse(Chain)}
- catch
- throw:_ ->
- {error, issuer_not_found}
+ {ok, Root, lists:reverse(Chain)};
+ {error, issuer_not_found} ->
+ {ok, unknown_crl_ca, []}
end.
find_issuer(CRL, {Db,_}) ->
@@ -61,11 +60,10 @@ find_issuer(CRL, {Db,_}) ->
issuer_not_found ->
{error, issuer_not_found}
catch
- {ok, IssuerCert} ->
- IssuerCert
+ {ok, _} = Result ->
+ Result
end.
-
verify_crl_issuer(CRL, ErlCertCandidate, Issuer, NotIssuer) ->
TBSCert = ErlCertCandidate#'OTPCertificate'.tbsCertificate,
case public_key:pkix_normalize_name(TBSCert#'OTPTBSCertificate'.subject) of