Skip to content

Commit 36d0a5c

Browse files
committed
Move to Crypt-OpenSSL-Verify as Crypt-OpenSSL-Verify is not supported
1 parent af050d5 commit 36d0a5c

File tree

10 files changed

+9
-46
lines changed

10 files changed

+9
-46
lines changed

Makefile.PL

+2-2
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ my %WriteMakefileArgs = (
2222
"Crypt::OpenSSL::DSA" => 0,
2323
"Crypt::OpenSSL::RSA" => 0,
2424
"Crypt::OpenSSL::Random" => 0,
25-
"Crypt::OpenSSL::VerifyX509" => 0,
25+
"Crypt::OpenSSL::Verify" => 0,
2626
"Crypt::OpenSSL::X509" => 0,
2727
"DateTime" => 0,
2828
"DateTime::Format::XSD" => 0,
@@ -82,7 +82,7 @@ my %FallbackPrereqs = (
8282
"Crypt::OpenSSL::DSA" => 0,
8383
"Crypt::OpenSSL::RSA" => 0,
8484
"Crypt::OpenSSL::Random" => 0,
85-
"Crypt::OpenSSL::VerifyX509" => 0,
85+
"Crypt::OpenSSL::Verify" => 0,
8686
"Crypt::OpenSSL::X509" => 0,
8787
"DateTime" => 0,
8888
"DateTime::Format::XSD" => 0,

cpanfile

+1-1
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ requires "Crypt::OpenSSL::Bignum" => "0";
44
requires "Crypt::OpenSSL::DSA" => "0";
55
requires "Crypt::OpenSSL::RSA" => "0";
66
requires "Crypt::OpenSSL::Random" => "0";
7-
requires "Crypt::OpenSSL::VerifyX509" => "0";
7+
requires "Crypt::OpenSSL::Verify" => "0";
88
requires "Crypt::OpenSSL::X509" => "0";
99
requires "DateTime" => "0";
1010
requires "DateTime::Format::XSD" => "0";

lib/Net/SAML2/Binding/POST.pm

+2-2
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ Net::SAML2::Binding::POST - HTTP POST binding for SAML2
2525

2626
use Net::SAML2::XML::Sig;
2727
use MIME::Base64 qw/ decode_base64 /;
28-
use Crypt::OpenSSL::VerifyX509;
28+
use Crypt::OpenSSL::Verify;
2929

3030
=head2 new( )
3131
@@ -69,7 +69,7 @@ sub handle_response {
6969
my $cert = $x->signer_cert
7070
or die "Certificate not provided and not in SAML Response, cannot validate";
7171

72-
my $ca = Crypt::OpenSSL::VerifyX509->new($self->cacert);
72+
my $ca = Crypt::OpenSSL::Verify->new($self->cacert, { strict_certs => 0, });
7373
if ($ca->verify($cert)) {
7474
return sprintf("%s (verified)", $cert->subject);
7575
} else {

lib/Net/SAML2/Binding/SOAP.pm

+2-2
Original file line numberDiff line numberDiff line change
@@ -121,7 +121,7 @@ sub handle_response {
121121

122122
# verify the signing certificate
123123
my $cert = $x->signer_cert;
124-
my $ca = Crypt::OpenSSL::VerifyX509->new($self->cacert);
124+
my $ca = Crypt::OpenSSL::Verify->new($self->cacert, { strict_certs => 0, });
125125
$ret = $ca->verify($cert);
126126
die "bad signer cert" unless $ret;
127127

@@ -159,7 +159,7 @@ sub handle_request {
159159
die "bad signature" unless $ret;
160160

161161
my $cert = $x->signer_cert;
162-
my $ca = Crypt::OpenSSL::VerifyX509->new($self->cacert);
162+
my $ca = Crypt::OpenSSL::Verify->new($self->cacert, { strict_certs => 0, });
163163
$ret = $ca->verify($cert);
164164
die "bad certificate in request: ".$cert->subject unless $ret;
165165

lib/Net/SAML2/IdP.pm

+2-2
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ Net::SAML2::IdP - SAML Identity Provider object
1616
1717
=cut
1818

19-
use Crypt::OpenSSL::VerifyX509;
19+
use Crypt::OpenSSL::Verify;
2020
use Crypt::OpenSSL::X509;
2121
use HTTP::Request::Common;
2222
use LWP::UserAgent;
@@ -180,7 +180,7 @@ sub BUILD {
180180
my($self) = @_;
181181

182182
if ($self->cacert) {
183-
my $ca = Crypt::OpenSSL::VerifyX509->new($self->cacert);
183+
my $ca = Crypt::OpenSSL::Verify->new($self->cacert, { strict_certs => 0, });
184184

185185
for my $use (keys %{$self->certs}) {
186186
my $cert = Crypt::OpenSSL::X509->new_from_string($self->certs->{$use});

t/01-create-idp.t

-2
Original file line numberDiff line numberDiff line change
@@ -55,8 +55,6 @@ Iavyic/p4gZtXckweq+VTn9CdZp6ZTQtVw==
5555
</EntityDescriptor>
5656
XML
5757

58-
my $override = override_verify_x509_verify(1);
59-
6058
my $idp = Net::SAML2::IdP->new_from_xml(
6159
xml => $xml,
6260
cacert => 't/cacert.pem'

t/04-response.t

-2
Original file line numberDiff line numberDiff line change
@@ -61,8 +61,6 @@ XML
6161

6262
my $response = encode_base64($xml);
6363

64-
my $override = override_verify_x509_verify(1);
65-
6664
my $sp = net_saml2_sp();
6765

6866
my $post = $sp->post_binding;

t/05-soap-binding.t

-2
Original file line numberDiff line numberDiff line change
@@ -5,8 +5,6 @@ use Net::SAML2::IdP;
55

66
use LWP::UserAgent;
77

8-
my $override = override_verify_x509_verify(1);
9-
108
my $sp = net_saml2_sp();
119

1210
my $metadata = path('t/idp-metadata.xml')->slurp;

t/06-redirect-binding.t

-7
Original file line numberDiff line numberDiff line change
@@ -14,13 +14,6 @@ my $idp = Net::SAML2::IdP->new_from_xml(
1414

1515
isa_ok($idp, "Net::SAML2::IdP");
1616

17-
my $override = override_verify_x509_verify(1);
18-
$override->override(
19-
'Net::SAML2::Util::generate_id' => sub {
20-
return 'myid';
21-
}
22-
);
23-
2417
my $sso_url = $idp->sso_url($idp->binding('redirect'));
2518
is(
2619
$sso_url,

t/lib/Test/Net/SAML2/Util.pm

-24
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,6 @@ require Exporter;
88
our @ISA = qw(Exporter);
99
our @EXPORT = qw(
1010
get_xpath
11-
override
12-
override_verify_x509_verify
1311
test_xml_attribute_ok
1412
test_xml_value_ok
1513
net_saml2_sp
@@ -84,28 +82,6 @@ sub test_xml_value_ok {
8482
return 0;
8583
}
8684

87-
sub override {
88-
return Sub::Override->override(@_);
89-
}
90-
91-
# On debian testing we have an issue with an underlying module. For one
92-
# reason or another I have the module installed, but it breaks on
93-
# reinstallation. So we mock the module
94-
#
95-
# TODO: https://gitlab.com/waterkip/perl-net-saml2/issues/1
96-
sub override_verify_x509_verify {
97-
my $return_ok = shift;
98-
99-
return override(
100-
'Crypt::OpenSSL::VerifyX509::verify' => sub {
101-
return $return_ok if $return_ok;
102-
die
103-
104-
"override of Crypt::OpenSSL::VerifyX509::verify says failure!";
105-
}
106-
);
107-
}
108-
10985
sub looks_like_a_cert {
11086
my $cert = shift;
11187
lives_ok(

0 commit comments

Comments
 (0)