Re: [exim-dev] tls_in_peerdn/tls_in_peercert for unverified …

Startseite
Nachricht löschen
Nachricht beantworten
Autor: Jeremy Harris
Datum:  
To: exim-dev
Betreff: Re: [exim-dev] tls_in_peerdn/tls_in_peercert for unverified certificate
On 25/12/14 21:19, Roman Rybalko wrote:
> Please, check my pull request: https://github.com/Exim/exim/pull/24


- Doesn't do anything for GnuTLS builds
- Wastefully dups every link in a CA-anchored chain
- Depends on undocumented behaviour of OpenSSL; that
the verify callback will always be called for every certificate
chain element, including when a nonterminal certificate
does not verify
- Does not work for DANE-anchored chains
- Needs documentation
--
Cheers,
Jeremy