From 223cc9623992db8f30918abf310aaa7528f83f82 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Thu, 19 Sep 2019 15:03:21 +0200 Subject: [PATCH] options: Do not attempt to expand percents in PKCS#11 URIs With the old token parser, the data was simply broken on the = sign even if the uri was in quotes and ignored. Signed-off-by: Jakub Jelen Reviewed-by: Anderson Toshiyuki Sasaki --- src/options.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/src/options.c b/src/options.c index 672735a4..d9799e86 100644 --- a/src/options.c +++ b/src/options.c @@ -1472,6 +1472,13 @@ int ssh_options_apply(ssh_session session) { it != NULL; it = it->next) { char *id = (char *) it->data; + if (strncmp(id, "pkcs11:", 6) == 0) { + /* PKCS#11 URIs are using percent-encoding so we can not mix + * it with ssh expansion of ssh escape characters. + * Skip these identities now, before we will have PKCS#11 support + */ + continue; + } tmp = ssh_path_expand_escape(session, id); if (tmp == NULL) { return -1;