Commit 82eef37eb9 for openssl.org
commit 82eef37eb9c1111e24dec960a5c7d10ffb122fb0
Author: Eugene Syromiatnikov <esyr@openssl.org>
Date: Fri Oct 2 18:54:23 2026 +0200
apps/x509.c: don't load extensions if no -extfile/-extensions/"extensions" opt
The documentation says "If neither of the options are given, an attempt
is made to open the default configuration file [..] If the unnamed
section [..] of the file does not list an B<extensions> variable,
no extensions are added"; however, an attempt was made to load
extensions in that case. Avoid that by using non-NULL extsect
as a guard for do_EXT_REQ_add_nconf() and do_EXT_REQ_add_nconf() calls
(which also avoids passing NULL as an "%s" format qualifier argument
to BIO_printf() calls in case of load failure).
Fixes: 84419e373ac1 "Improved handling of AKID/SKID extensions in CSRs and certs"
Signed-off-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Neil Horman <nhorman@openssl.org>
Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Reviewed-by: Bob Beck <beck@openssl.org>
Reviewed-by: Viktor Dukhovni <viktor@openssl.org>
Merge-date: Mon Oct 5 10:09:56 2026
Merged-from: https://github.com/openssl/openssl/pull/33083
diff --git a/apps/x509.c b/apps/x509.c
index baf4da16f7..c8cd9229f4 100644
--- a/apps/x509.c
+++ b/apps/x509.c
@@ -837,13 +837,21 @@ int x509_main(int argc, char **argv)
if (extsect == NULL) {
extsect = app_conf_try_string(extconf, "default", "extensions");
+ /*
+ * If neither -extfile nor -extensions is provided, and the default
+ * config file's default section doesn't contain the "extensions"
+ * config option, extsect is left as NULL, which is then used
+ * as an indicator to avoid trying to load extensions.
+ */
if (extfile != NULL && extsect == NULL)
extsect = "default";
}
- X509V3_set_ctx_test(&ctx2);
- if (!do_EXT_add_nconf(extconf, extconf, &ctx2, NULL,
- "Error checking extension section %s\n", extsect))
- goto err;
+ if (extsect != NULL) {
+ X509V3_set_ctx_test(&ctx2);
+ if (!do_EXT_add_nconf(extconf, extconf, &ctx2, NULL,
+ "Error checking extension section %s\n", extsect))
+ goto err;
+ }
} else if (newout && !confquiet) {
goto err;
}
@@ -1009,7 +1017,7 @@ cert_loop:
if (!X509V3_set_issuer_pkey(&ext_ctx, privkey))
goto err;
}
- if (extconf != NULL && !x509toreq) {
+ if (extconf != NULL && !x509toreq && extsect != NULL) {
if (!do_EXT_add_nconf(extconf, extconf, &ext_ctx, x,
"Error adding extensions from section %s\n", extsect))
goto err;
@@ -1034,7 +1042,7 @@ cert_loop:
}
if ((rq = x509_to_req(x, ext_copy, ext_names)) == NULL)
goto err;
- if (extconf != NULL) {
+ if (extconf != NULL && extsect != NULL) {
if (!do_EXT_REQ_add_nconf(extconf, extconf, &ext_ctx, rq,
"Error adding request extensions from section %s\n", extsect))
goto err;