Browse Source

lwm2m - cert trust must be signed certServer with 'CN' = {CN by server}

pull/5661/head
nickAS21 5 years ago
parent
commit
f0d3e31e17
  1. 2
      common/transport/lwm2m/src/main/java/org/thingsboard/server/transport/lwm2m/secure/TbLwM2MDtlsCertificateVerifier.java
  2. BIN
      transport/lwm2m/src/main/data/lwm2mserver.jks

2
common/transport/lwm2m/src/main/java/org/thingsboard/server/transport/lwm2m/secure/TbLwM2MDtlsCertificateVerifier.java

@ -199,7 +199,7 @@ public class TbLwM2MDtlsCertificateVerifier implements NewAdvancedCertificateVer
for (int index = 0; index < certificates.length; ++index) {
X509Certificate trust = certificates[index];
String trustCN = config.getTrustSslCredentials().getValueFromSubjectNameByKey(trust.getSubjectX500Principal().getName(), "CN");
if (!StringUtils.isBlank(trustCN) && issuerCN.length() > trustCN.length() && issuerCN.substring(issuerCN.length()-trustCN.length()).equals(trustCN)) {
if (!StringUtils.isBlank(trustCN) && issuerCN.length() >= trustCN.length() && issuerCN.substring(issuerCN.length()-trustCN.length()).equals(trustCN)) {
if (verifyCertificate(certificate)) {
return certificate;
}

BIN
transport/lwm2m/src/main/data/lwm2mserver.jks

Binary file not shown.
Loading…
Cancel
Save