Closed
Bug 2066048
Opened 1 month ago
Closed 2 days ago
Apply SSL_DB_LOAD_CERTIFICATE_CHAIN to leaf certificates
Categories
(NSS :: Libraries, enhancement, P3)
NSS
Libraries
Tracking
(nss 3.131)
RESOLVED
FIXED
| Tracking | Status | |
|---|---|---|
| nss | --- | 3.131 |
People
(Reporter: djackson, Assigned: djackson)
References
(Blocks 1 open bug)
Details
Attachments
(2 files)
No description provided.
| Assignee | ||
Comment 1•1 month ago
|
||
The option controls importing "the peer certificate chain", but the end-entity
certificate was imported before it was consulted; only the intermediates
honoured it. With the option off, a client's peer certificate is now only
decoded. Servers are unchanged.
SSL_PeerCertificateChain() and SSL_AuthCertificate() need the database's copy
regardless, one for path finding and the other for the trust record, so both
re-derive it.
Comment 2•1 month ago
|
||
Updated•1 month ago
|
Attachment #9631367 -
Attachment description: WIP: Bug 2066048 - replace sslSecurityInfo peerCert with peerCertDER. → Bug 2066048 - replace sslSecurityInfo peerCert with peerCertDER. r=#nss-reviewers
Pushed by jschanck@mozilla.com:
https://hg.mozilla.org/projects/nss/rev/8b32d1d997f0
replace sslSecurityInfo peerCert with peerCertDER. r=keeler
Status: NEW → RESOLVED
Closed: 2 days ago
Resolution: --- → FIXED
| Assignee | ||
Updated•1 day ago
|
status-nss:
--- → 3.131
You need to log in
before you can comment on or make changes to this bug.
Description
•