1. 30 May, 2018 1 commit
  2. 29 May, 2018 1 commit
  3. 26 May, 2018 1 commit
  4. 24 May, 2018 2 commits
  5. 23 May, 2018 2 commits
    • Viktor Dukhovni's avatar
      Skip CN DNS name constraint checks when not needed · 6d3cfd13
      Viktor Dukhovni authored
      
      
      Only check the CN against DNS name contraints if the
      `X509_CHECK_FLAG_NEVER_CHECK_SUBJECT` flag is not set, and either the
      certificate has no DNS subject alternative names or the
      `X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT` flag is set.
      
      Add pertinent documentation, and touch up some stale text about
      name checks and DANE.
      
      Reviewed-by: default avatarMatt Caswell <matt@openssl.org>
      Reviewed-by: default avatarTim Hudson <tjh@openssl.org>
      6d3cfd13
    • Viktor Dukhovni's avatar
      Limit scope of CN name constraints · c2c2c7b3
      Viktor Dukhovni authored
      
      
      Don't apply DNS name constraints to the subject CN when there's a
      least one DNS-ID subjectAlternativeName.
      
      Don't apply DNS name constraints to subject CN's that are sufficiently
      unlike DNS names.  Checked name must have at least two labels, with
      all labels non-empty, no trailing '.' and all hyphens must be
      internal in each label.  In addition to the usual LDH characters,
      we also allow "_", since some sites use these for hostnames despite
      all the standards.
      
      Reviewed-by: default avatarMatt Caswell <matt@openssl.org>
      Reviewed-by: default avatarTim Hudson <tjh@openssl.org>
      c2c2c7b3
  6. 21 May, 2018 2 commits
  7. 20 May, 2018 3 commits
  8. 19 May, 2018 1 commit
  9. 18 May, 2018 1 commit
  10. 17 May, 2018 2 commits
  11. 16 May, 2018 1 commit
  12. 15 May, 2018 1 commit
  13. 14 May, 2018 2 commits
  14. 12 May, 2018 3 commits
  15. 11 May, 2018 5 commits
  16. 08 May, 2018 1 commit
  17. 05 May, 2018 2 commits
  18. 04 May, 2018 3 commits
  19. 03 May, 2018 2 commits
  20. 02 May, 2018 4 commits