Closed Bug 2066048 Opened 1 month ago Closed 2 days ago

Apply SSL_DB_LOAD_CERTIFICATE_CHAIN to leaf certificates

Categories

(NSS :: Libraries, enhancement, P3)

enhancement

Tracking

(nss 3.131)

RESOLVED FIXED
Tracking Status
nss --- 3.131

People

(Reporter: djackson, Assigned: djackson)

References

(Blocks 1 open bug)

Details

Attachments

(2 files)

No description provided.

The option controls importing "the peer certificate chain", but the end-entity
certificate was imported before it was consulted; only the intermediates
honoured it. With the option off, a client's peer certificate is now only
decoded. Servers are unchanged.

SSL_PeerCertificateChain() and SSL_AuthCertificate() need the database's copy
regardless, one for path finding and the other for the trust record, so both
re-derive it.

Attachment #9631367 - Attachment description: WIP: Bug 2066048 - replace sslSecurityInfo peerCert with peerCertDER. → Bug 2066048 - replace sslSecurityInfo peerCert with peerCertDER. r=#nss-reviewers

Pushed by jschanck@mozilla.com:
https://hg.mozilla.org/projects/nss/rev/8b32d1d997f0
replace sslSecurityInfo peerCert with peerCertDER. r=keeler

Status: NEW → RESOLVED
Closed: 2 days ago
Resolution: --- → FIXED
status-nss: --- → 3.131
See Also: → 2079517
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: