From: Dr. Stephen Henson Date: Fri, 7 Dec 2001 00:36:32 +0000 (+0000) Subject: Don't overwrite signing time. X-Git-Tag: OpenSSL-engine-0_9_6c^2^2~156 X-Git-Url: https://git.librecmc.org/?a=commitdiff_plain;h=f3e24baddfdab36524ab8172edf0f7f4b15666be;p=oweals%2Fopenssl.git Don't overwrite signing time. --- diff --git a/CHANGES b/CHANGES index ceceb0e03b..1c9c7fd35c 100644 --- a/CHANGES +++ b/CHANGES @@ -12,6 +12,9 @@ *) applies to 0.9.6a/0.9.6b/0.9.6c and 0.9.7 +) applies to 0.9.7 only + *) Only add signing time to PKCS7 structures if it is not already present. + [Steve Henson] + *) Fix crypto/objects/objects.h: "ld-ce" should be "id-ce", OBJ_ld_ce should be OBJ_id_ce. Also some ip-pda OIDs in crypto/objects/objects.txt were diff --git a/crypto/pkcs7/pk7_doit.c b/crypto/pkcs7/pk7_doit.c index 5b803b0266..fce4a841a6 100644 --- a/crypto/pkcs7/pk7_doit.c +++ b/crypto/pkcs7/pk7_doit.c @@ -557,11 +557,15 @@ int PKCS7_dataFinal(PKCS7 *p7, BIO *bio) ASN1_UTCTIME *sign_time; const EVP_MD *md_tmp; - /* Add signing time */ - sign_time=X509_gmtime_adj(NULL,0); - PKCS7_add_signed_attribute(si, - NID_pkcs9_signingTime, - V_ASN1_UTCTIME,sign_time); + /* Add signing time if not already present */ + if (!PKCS7_get_signed_attribute(si, + NID_pkcs9_signingTime)) + { + sign_time=X509_gmtime_adj(NULL,0); + PKCS7_add_signed_attribute(si, + NID_pkcs9_signingTime, + V_ASN1_UTCTIME,sign_time); + } /* Add digest */ md_tmp=EVP_MD_CTX_md(&ctx_tmp);