Commit f80e188
committed
internal: re-verify restored ticket peer cert against trust store
RestorePeerCertFromTicket passed verify=0 and CertificateManager=NULL to
ParseCertRelative, so a ticket-restored peer cert was decoded and installed
without any CRL/OCSP or trust-walk opportunity. A principal whose CA was
removed or whose cert was revoked after ticket issuance remained valid for
the full ticket lifetime. Pass SSL_CM(ssl) and honor verifyPeer so the
restored cert is re-checked on every resumption.1 parent a9acc12 commit f80e188
1 file changed
Lines changed: 5 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
39686 | 39686 | | |
39687 | 39687 | | |
39688 | 39688 | | |
| 39689 | + | |
39689 | 39690 | | |
39690 | | - | |
| 39691 | + | |
| 39692 | + | |
| 39693 | + | |
| 39694 | + | |
39691 | 39695 | | |
39692 | 39696 | | |
39693 | 39697 | | |
| |||
0 commit comments