On Mon, Dec 17, 2012, Giovani Milanez wrote:
> Hello,
> i was trying to extract Authority Information Access extension from a
> certificate and realize that my code was leaking memory.
>
> You can try:
>
> X509 *cert; //you should load your certificate and place here
> X509_EXTENSION *ext;
>
> int extCount = X509_get_ext_count(cert);
> for (int i=0;i<extCount;i++)
> {
> ext = X509_get_ext(cert, i);
> if(OBJ_obj2nid(ext->object) == NID_info_access){
> AUTHORITY_INFO_ACCESS *aia = (AUTHORITY_INFO_ACCESS
> *)X509V3_EXT_d2i(ext);
> for(int i = 0; i < sk_ACCESS_DESCRIPTION_num(aia); i++){
> ACCESS_DESCRIPTION *desc = sk_ACCESS_DESCRIPTION_value(aia,
> i);
>
> ACCESS_DESCRIPTION *duped = ACCESS_DESCRIPTION_new();
> //since we dont have ACCESS_DESCRIPTION_dup, we do it manually
> duped->location = GENERAL_NAME_dup(desc->location);
> duped->method = OBJ_dup(desc->method);
> ACCESS_DESCRIPTION_free(duped); //is it clearing properly
> the method?
> }
> AUTHORITY_INFO_ACCESS_free(aia);
> }
> }
>
> In my case i need to dup the ACCESS_DESCRIPTION because i would use it in
> another class that takes ownership of the pointer.
>
One unrelated observation. You can simplify the initial code by doing:
aia = X509_get_ext_d2i(cert, NID_info_access, NULL, NULL);
Steve.
--
Dr Stephen N. Henson. OpenSSL project core developer.
Commercial tech support now available see: http://www.openssl.org
______________________________________________________________________
OpenSSL Project http://www.openssl.org
User Support Mailing List [email protected]
Automated List Manager [email protected]