1
0
镜像自地址 git://git.gnupg.org/gnupg.git 已同步 2025-06-30 22:27:56 +02:00

agent: Skip unknown unknown ssh curves seen on cards.

* agent/command-ssh.c (ssh_handler_request_identities): Skip unknown
curves.
--

For example when using my standard ed25519 token and testing cards
with only Brainpool support, the ssh-agent failed due to the unknown
curves seen on the card.  This patches fixes this by ignoring keys
with unknown curves.

Signed-off-by: Werner Koch <wk@gnupg.org>
这个提交包含在:
Werner Koch 2021-03-29 15:39:32 +02:00
父节点 a494b29af9
当前提交 2d2391dfc2
找不到此签名对应的密钥
GPG 密钥 ID: E3FDFF218E45B72B

查看文件

@ -2513,18 +2513,28 @@ ssh_handler_request_identities (ctrl_t ctrl,
continue;
err = ssh_send_key_public (key_blobs, key_public, cardsn);
if (err && opt.verbose)
gcry_log_debugsxp ("pubkey", key_public);
gcry_sexp_release (key_public);
key_public = NULL;
xfree (cardsn);
if (err)
{
agent_card_free_keyinfo (keyinfo_list);
goto out;
if (err && opt.verbose)
gcry_log_debugsxp ("pubkey", key_public);
if (gpg_err_code (err) == GPG_ERR_UNKNOWN_CURVE
|| gpg_err_code (err) == GPG_ERR_INV_CURVE)
{
/* For example a Brainpool curve or a curve we don't
* support at all but a smartcard lists that curve.
* We ignore them. */
}
else
{
agent_card_free_keyinfo (keyinfo_list);
goto out;
}
}
key_counter++;
else
key_counter++;
}
agent_card_free_keyinfo (keyinfo_list);