Skip to content
Commit 6e328256 authored by Viktor Dukhovni's avatar Viktor Dukhovni
Browse files

Check Suite-B constraints with EE DANE records



When DANE-EE(3) matches or either of DANE-EE/PKIX-EE fails, we don't
build a chain at all, but rather succeed or fail with just the leaf
certificate.  In either case also check for Suite-B violations.

As unlikely as it may seem that anyone would enable both DANE and
Suite-B, we should do what the application asks.

Took the opportunity to eliminate the "cb" variables in x509_vfy.c,
just call ctx->verify_cb(ok, ctx)

Reviewed-by: default avatarDr. Stephen Henson <steve@openssl.org>
parent bd5192b1
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment