summaryrefslogtreecommitdiffstats
path: root/apps/crl.c
diff options
context:
space:
mode:
authorDr. Stephen Henson <steve@openssl.org>2016-08-16 15:19:55 +0100
committerDr. Stephen Henson <steve@openssl.org>2016-08-16 16:05:36 +0100
commit0f022f5a2201a591da7d373ebeeb7d29bdcaf95a (patch)
treeb7c52530cafda1d0f8c558e70962cff1817c2d91 /apps/crl.c
parent34d4d74575236245c7e133d121eb2302c18b21f1 (diff)
Corrupt signature earlier.
If -badsig is selected corrupt the signature before printing out any details so the output reflects the modified signature. Reviewed-by: Rich Salz <rsalz@openssl.org>
Diffstat (limited to 'apps/crl.c')
-rw-r--r--apps/crl.c15
1 files changed, 8 insertions, 7 deletions
diff --git a/apps/crl.c b/apps/crl.c
index 6ea0b4c32b..0140ff749c 100644
--- a/apps/crl.c
+++ b/apps/crl.c
@@ -249,6 +249,14 @@ int crl_main(int argc, char **argv)
}
}
+ if (badsig) {
+ ASN1_BIT_STRING *sig;
+
+ X509_CRL_get0_signature(&sig, NULL, x);
+ if (!corrupt_signature(sig))
+ goto end;
+ }
+
if (num) {
for (i = 1; i <= num; i++) {
if (issuer == i) {
@@ -319,13 +327,6 @@ int crl_main(int argc, char **argv)
goto end;
}
- if (badsig) {
- ASN1_BIT_STRING *sig;
- X509_CRL_get0_signature(&sig, NULL, x);
- if (!corrupt_signature(sig))
- goto end;
- }
-
if (outformat == FORMAT_ASN1)
i = (int)i2d_X509_CRL_bio(out, x);
else