Repository navigation
use Locale.ENGLISH for address folding in SignedMailValidator - #2485
rootvector2 wants to merge 1 commit into
Conversation
…ower cased in ASCII only, independently of the default locale, incorporating github PR #2485.
|
maybe |
|
They fold identically: the only locale-specific case rules are the |
|
Thanks for the PR! This has merged with some changes, principally it was modified to use Strings.toLowerCase() which only affects ascii characters and ignores the Locale, this felt like it better met the original intention of the patch. Result is now up on https://www.bouncycastle.org/betas let us know how it goes. |
SignedMailValidatorfolds both sides of the comparison that ties a signature to the sender the message claims, the certificate's email addresses ingetEmailAddressesand theFromaddresses inhasAnyFromAddress, withLocale.getDefault()captured in a static field at class load, so on a Turkish or Azerbaijani JVMIlower cases to the dotlessıand a legitimately signed message is reported asemailFromCertMismatchwhile a certificate whoseemailAddressattribute carriesU+0130(the attribute is read throughASN1String, not restricted toIA5String) folds onto a different mailbox and satisfies the check for it; found sweeping every module'ssrc/mainfor case conversion used in a security comparison, which turned up this as the only default-locale one, the JSSEHostnameUtil,BCSNIHostNameandDisabledAlgorithmConstraintsall fixingLocale.ENGLISHand the EST hostname authorizer using the locale-independentStrings.toLowerCase.AI tooling was used to help prepare this change.