• V
    Enabled DANE only when at least one TLSA RR was added · 9f6b22b8
    Viktor Dukhovni 提交于
    It is up to the caller of SSL_dane_tlsa_add() to take appropriate
    action when no records are added successfully or adding some records
    triggers an internal error (negative return value).
    
    With this change the caller can continue with PKIX if desired when
    none of the TLSA records are usable, or take some appropriate action
    if DANE is required.
    
    Also fixed the internal ssl_dane_dup() function to properly initialize
    the TLSA RR stack in the target SSL handle.  Errors in ssl_dane_dup()
    are no longer ignored.
    Reviewed-by: NRich Salz <rsalz@openssl.org>
    9f6b22b8
SSL_CTX_dane_enable.pod 13.3 KB