Skip to content
11 changes: 11 additions & 0 deletions src/main/java/com/jcraft/jsch/IdentityFile.java
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,8 @@

package com.jcraft.jsch;

import java.util.Arrays;

class IdentityFile implements Identity {
private KeyPair kpair;
private String identity;
Expand All @@ -40,6 +42,15 @@ static IdentityFile newInstance(String name, byte[] prvkey, byte[] pubkey,
JSch.InstanceLogger instLogger) throws JSchException {

KeyPair kpair = KeyPair.load(instLogger, prvkey, pubkey);
// if both keys are provided, make sure they match
if(prvkey != null && pubkey != null) {
KeyPair kpairVal = KeyPair.load(instLogger, null, pubkey);
if(kpairVal == null)
throw new JSchException("invalid publickey");
if(!Arrays.equals(kpair.getPublicKeyBlob(),
Comment thread
AlainKnaff marked this conversation as resolved.
Outdated
kpairVal.getPublicKeyBlob()))
throw new JSchException("Public key does not match private key");
}
return new IdentityFile(name, kpair);
}

Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
package com.jcraft.jsch;

import java.util.Arrays;
import java.io.IOException;
import java.nio.charset.StandardCharsets;

Expand Down Expand Up @@ -169,6 +170,9 @@
throw new JSchException("Invalid certificate: missing public key");
}
kpair = KeyPair.load(instLogger, prvkey, certPublicKey);
if(prvkey != null &&
!Arrays.equals(kpair.getPublicKeyBlob(), certPublicKey))

Check failure on line 174 in src/main/java/com/jcraft/jsch/OpenSshCertificateAwareIdentityFile.java

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use indentation to denote the code conditionally executed by this "if".

See more on https://sonarcloud.io/project/issues?id=mwiede_jsch&issues=AaDzvqWPZVmGKJNUFSPO&open=AaDzvqWPZVmGKJNUFSPO&pullRequest=1168
Comment thread
AlainKnaff marked this conversation as resolved.
Outdated
throw new JSchException("Certificate does not match private key");

} catch (IllegalArgumentException e) {
throw new JSchException("Invalid certificate format: " + e.getMessage(), e);
Expand Down
Loading