d95ab8d3a3
Once the signing key is taken from the matching SfxViewShell (not yet
done), signing with a certificate specified via initializeForRendering()
failed with:
warn:xmlsecurity.xmlsec:13020:13005:xmlsecurity/source/xmlsec/nss/x509certificate_nssimpl.cxx:330: X509Certificate_NssImpl::getPrivateKey() cannot find private key
warn:xmlsecurity.xmlsec:13020:13005:xmlsecurity/source/xmlsec/nss/securityenvironment_nssimpl.cxx:812: Can't get the private key from the certificate.
warn:xmlsecurity.xmlsec:13020:13005:xmlsecurity/source/xmlsec/errorcallback.cxx:53: keys.c:1347: xmlSecKeysMngrGetKey() '' '' 45 'details=NULL'
warn:xmlsecurity.xmlsec:13020:13005:xmlsecurity/source/xmlsec/errorcallback.cxx:53: xmldsig.c:822: xmlSecDSigCtxProcessKeyInfoNode() '' '' 45 'details=NULL'
warn:xmlsecurity.xmlsec:13020:13005:xmlsecurity/source/xmlsec/errorcallback.cxx:53: xmldsig.c:537: xmlSecDSigCtxProcessSignatureNode() '' 'xmlSecDSigCtxProcessKeyInfoNode' 1 ' '
warn:xmlsecurity.xmlsec:13020:13005:xmlsecurity/source/xmlsec/errorcallback.cxx:53: xmldsig.c:301: xmlSecDSigCtxSign() '' 'xmlSecDSigCtxProcessSignatureNode' 1 ' '
The trouble was that we wanted to keep the private key in-memory,
presumably because initially the whole NSS database was in-memory for
the LOK case. This was changed in commit
87eec1b90b
(NSS: create a temporary
database instead of in-memory, 2018-12-31), so there is no problem with
a not-in-memory private key anymore.
Note that the problematic codepath was only triggered when first the
certificate chooser was ran and only then we signed. So the testcase
also gets the cert flags before signing, otherwise the test would
succeed even without the fix.
Change-Id: I5086b205c91b630ddd343c0eb91bd9e63b3ea238
Reviewed-on: https://gerrit.libreoffice.org/c/core/+/173892
Reviewed-by: Miklos Vajna <vmiklos@collabora.com>
Tested-by: Jenkins
56 lines
1.5 KiB
Makefile
56 lines
1.5 KiB
Makefile
# -*- Mode: makefile-gmake; tab-width: 4; indent-tabs-mode: t -*-
|
|
#*************************************************************************
|
|
#
|
|
# This file is part of the LibreOffice project.
|
|
#
|
|
# This Source Code Form is subject to the terms of the Mozilla Public
|
|
# License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
# file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
#
|
|
#*************************************************************************
|
|
|
|
$(eval $(call gb_CppunitTest_CppunitTest,xmlsecurity_xmlsec))
|
|
|
|
$(eval $(call gb_CppunitTest_use_externals,xmlsecurity_xmlsec,\
|
|
boost_headers \
|
|
))
|
|
|
|
$(eval $(call gb_CppunitTest_add_exception_objects,xmlsecurity_xmlsec, \
|
|
xmlsecurity/qa/xmlsec/xmlsec \
|
|
))
|
|
|
|
$(eval $(call gb_CppunitTest_use_libraries,xmlsecurity_xmlsec, \
|
|
comphelper \
|
|
cppu \
|
|
cppuhelper \
|
|
embobj \
|
|
sal \
|
|
sfx \
|
|
subsequenttest \
|
|
test \
|
|
tl \
|
|
unotest \
|
|
utl \
|
|
xmlsecurity \
|
|
xsec_xmlsec \
|
|
))
|
|
|
|
$(eval $(call gb_CppunitTest_set_include,xmlsecurity_xmlsec,\
|
|
-I$(SRCDIR)/xmlsecurity/inc \
|
|
$$(INCLUDE) \
|
|
))
|
|
|
|
$(eval $(call gb_CppunitTest_use_sdk_api,xmlsecurity_xmlsec))
|
|
|
|
$(eval $(call gb_CppunitTest_use_ure,xmlsecurity_xmlsec))
|
|
$(eval $(call gb_CppunitTest_use_vcl,xmlsecurity_xmlsec))
|
|
|
|
$(eval $(call gb_CppunitTest_use_rdb,xmlsecurity_xmlsec,services))
|
|
|
|
$(eval $(call gb_CppunitTest_use_custom_headers,xmlsecurity_xmlsec,\
|
|
officecfg/registry \
|
|
))
|
|
|
|
$(eval $(call gb_CppunitTest_use_configuration,xmlsecurity_xmlsec))
|
|
|
|
# vim: set noet sw=4 ts=4:
|