• D
    Add new "valid_flags" field to CERT_PKEY structure which determines what · d61ff83b
    Dr. Stephen Henson 提交于
    the certificate can be used for (if anything). Set valid_flags field
    in new tls1_check_chain function. Simplify ssl_set_cert_masks which used
    to have similar checks in it.
    
    Add new "cert_flags" field to CERT structure and include a "strict mode".
    This enforces some TLS certificate requirements (such as only permitting
    certificate signature algorithms contained in the supported algorithms
    extension) which some implementations ignore: this option should be used
    with caution as it could cause interoperability issues.
    d61ff83b
s_server.c 84.8 KB