Skip to content

match a wildcard only in the leftmost label in match_hostname - #2619

Merged
yhirose merged 2 commits into
yhirose:masterfrom
metsw24-max:wildcard-leftmost-label
Oct 8, 2026
Merged

yhirose merged 2 commits into
yhirose:masterfrom
metsw24-max:wildcard-leftmost-label

Conversation

@metsw24-max

Copy link
Copy Markdown
Contributor

Wildcard honoured outside the leftmost label in match_hostname

detail::match_hostname treats any pattern label ending in * as a wildcard, so a certificate presenting www.*.example.test authenticates www.evil.example.test, and *.* authenticates every two-label host; the Mbed TLS and wolfSSL backends route both their dNSName and CN comparisons through it. OpenSSL's X509_check_host() already refuses a wildcard anywhere but the leftmost label (RFC 6125 6.4.3), so this restricts it the same way and leaves the deliberate prefix* form alone.

SSLClientServerTest.TlsVerifyHostnameWildcardLabel covers it against a new cert_wildcard_san.pem; it fails on Mbed TLS and wolfSSL before the change and passes on all three backends after.

@yhirose
yhirose merged commit 8f094fe into yhirose:master Oct 8, 2026
28 checks passed
@yhirose

yhirose commented Oct 8, 2026

Copy link
Copy Markdown
Owner

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants