Bastien Nocera 653a5af
From 3c1ca82ba31945de4e673525afb4774189011ce4 Mon Sep 17 00:00:00 2001
Bastien Nocera 653a5af
From: Bastien Nocera <hadess@hadess.net>
Bastien Nocera 653a5af
Date: Fri, 15 Sep 2017 16:02:42 +0200
Bastien Nocera 653a5af
Subject: [PATCH 2/2] userpref: [GnuTLS] Use valid serial for >= 3.6.0
Bastien Nocera 653a5af
Bastien Nocera 653a5af
Another change in 3.6.0 is that a serial of '\0' is not valid anymore.
Bastien Nocera 653a5af
Bump it to one.
Bastien Nocera 653a5af
---
Bastien Nocera 653a5af
 common/userpref.c | 6 +++---
Bastien Nocera 653a5af
 1 file changed, 3 insertions(+), 3 deletions(-)
Bastien Nocera 653a5af
Bastien Nocera 653a5af
diff --git a/common/userpref.c b/common/userpref.c
Bastien Nocera 653a5af
index f496fee..be745cb 100644
Bastien Nocera 653a5af
--- a/common/userpref.c
Bastien Nocera 653a5af
+++ b/common/userpref.c
Bastien Nocera 653a5af
@@ -598,7 +598,7 @@ userpref_error_t pair_record_generate_keys_and_certs(plist_t pair_record, key_da
Bastien Nocera 653a5af
 
Bastien Nocera 653a5af
 	/* generate certificates */
Bastien Nocera 653a5af
 	gnutls_x509_crt_set_key(root_cert, root_privkey);
Bastien Nocera 653a5af
-	gnutls_x509_crt_set_serial(root_cert, "\x00", 1);
Bastien Nocera 653a5af
+	gnutls_x509_crt_set_serial(root_cert, "\x01", 1);
Bastien Nocera 653a5af
 	gnutls_x509_crt_set_version(root_cert, 3);
Bastien Nocera 653a5af
 	gnutls_x509_crt_set_ca_status(root_cert, 1);
Bastien Nocera 653a5af
 	gnutls_x509_crt_set_activation_time(root_cert, time(NULL));
Bastien Nocera 653a5af
@@ -606,7 +606,7 @@ userpref_error_t pair_record_generate_keys_and_certs(plist_t pair_record, key_da
Bastien Nocera 653a5af
 	gnutls_x509_crt_sign2(root_cert, root_cert, root_privkey, GNUTLS_DIG_SHA1, 0);
Bastien Nocera 653a5af
 
Bastien Nocera 653a5af
 	gnutls_x509_crt_set_key(host_cert, host_privkey);
Bastien Nocera 653a5af
-	gnutls_x509_crt_set_serial(host_cert, "\x00", 1);
Bastien Nocera 653a5af
+	gnutls_x509_crt_set_serial(host_cert, "\x01", 1);
Bastien Nocera 653a5af
 	gnutls_x509_crt_set_version(host_cert, 3);
Bastien Nocera 653a5af
 	gnutls_x509_crt_set_ca_status(host_cert, 0);
Bastien Nocera 653a5af
 	gnutls_x509_crt_set_key_usage(host_cert, GNUTLS_KEY_KEY_ENCIPHERMENT | GNUTLS_KEY_DIGITAL_SIGNATURE);
Bastien Nocera 653a5af
@@ -703,7 +703,7 @@ userpref_error_t pair_record_generate_keys_and_certs(plist_t pair_record, key_da
Bastien Nocera 653a5af
 		if (GNUTLS_E_SUCCESS == gnutls_error) {
Bastien Nocera 653a5af
 			/* now generate device certificate */
Bastien Nocera 653a5af
 			gnutls_x509_crt_set_key(dev_cert, fake_privkey);
Bastien Nocera 653a5af
-			gnutls_x509_crt_set_serial(dev_cert, "\x00", 1);
Bastien Nocera 653a5af
+			gnutls_x509_crt_set_serial(dev_cert, "\x01", 1);
Bastien Nocera 653a5af
 			gnutls_x509_crt_set_version(dev_cert, 3);
Bastien Nocera 653a5af
 			gnutls_x509_crt_set_ca_status(dev_cert, 0);
Bastien Nocera 653a5af
 			gnutls_x509_crt_set_activation_time(dev_cert, time(NULL));
Bastien Nocera 653a5af
-- 
Bastien Nocera 653a5af
2.14.1
Bastien Nocera 653a5af