3a59611726
So long as we're not getting rid of them (the certificate variants may be useful when we decouple from crypto/x509 anyway), get the types and bounds checks right. Also reject trailing data and require the input be a single element. Note: this is a slight compatibility risk, but we did it for SSL*_use_RSAPrivateKey_ASN1 previously and I think it's probably worth seeing if anything breaks here. Change-Id: I64fa3fc6249021ccf59584d68e56ff424a190082 Reviewed-on: https://boringssl-review.googlesource.com/6490 Reviewed-by: Adam Langley <agl@google.com> |
||
---|---|---|
.. | ||
openssl |