On Mon, Dec 17, 2012, Giovani Milanez wrote:

> Hello,
> i was trying to extract Authority Information Access extension from a
> certificate and realize that my code was leaking memory.
> 
> You can try:
> 
>     X509 *cert; //you should load your certificate and place here
>     X509_EXTENSION *ext;
> 
>     int extCount = X509_get_ext_count(cert);
>     for (int i=0;i<extCount;i++)
>     {
>         ext = X509_get_ext(cert, i);
>         if(OBJ_obj2nid(ext->object) == NID_info_access){
>             AUTHORITY_INFO_ACCESS *aia = (AUTHORITY_INFO_ACCESS
> *)X509V3_EXT_d2i(ext);
>             for(int i = 0; i < sk_ACCESS_DESCRIPTION_num(aia); i++){
>                 ACCESS_DESCRIPTION *desc = sk_ACCESS_DESCRIPTION_value(aia,
> i);
> 
>                 ACCESS_DESCRIPTION *duped = ACCESS_DESCRIPTION_new();
> //since we dont have ACCESS_DESCRIPTION_dup, we do it manually
>                 duped->location = GENERAL_NAME_dup(desc->location);
>                 duped->method = OBJ_dup(desc->method);
>                 ACCESS_DESCRIPTION_free(duped); //is it clearing properly
> the method?
>             }
>             AUTHORITY_INFO_ACCESS_free(aia);
>         }
>     }
> 
> In my case i need to dup the ACCESS_DESCRIPTION because i would use it in
> another class that takes ownership of the pointer.
> 

One unrelated observation. You can simplify the initial code by doing:

aia = X509_get_ext_d2i(cert, NID_info_access, NULL, NULL);

Steve.
--
Dr Stephen N. Henson. OpenSSL project core developer.
Commercial tech support now available see: http://www.openssl.org
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [email protected]
Automated List Manager                           [email protected]

Reply via email to