We set the export flag for 512 *bit* keys, not 512 *byte* ones.
authorRichard Levitte <levitte@openssl.org>
Thu, 19 Jun 2003 18:55:50 +0000 (18:55 +0000)
committerRichard Levitte <levitte@openssl.org>
Thu, 19 Jun 2003 18:55:50 +0000 (18:55 +0000)
PR: 587

crypto/x509/x509type.c

index 4af98214a8ec57e16074e715986d87565395708e..8fe1c5458314545581a6b223e9878d5d652de918 100644 (file)
@@ -112,7 +112,8 @@ int X509_certificate_type(X509 *x, EVP_PKEY *pkey)
                break;
                }
 
-       if (EVP_PKEY_size(pk) <= 512)
+       if (EVP_PKEY_size(pk) <= 512/8) /* /8 because it's 512 bits we look
+                                          for, not bytes */
                ret|=EVP_PKT_EXP;
        if(pkey==NULL) EVP_PKEY_free(pk);
        return(ret);