8bd1d07535
OpenSSL 1.0.2 (and thus BoringSSL) accepts keyUsage certSign or a Netscape CA certificate-type in lieu of basicConstraints in an intermediate certificate (unless X509_V_FLAG_X509_STRICT) is set. Update-Note: This change tightens the code so that basicConstraints is required for intermediate certificates when verifying chains. This was previously only enabled if X509_V_FLAG_X509_STRICT was set, but that flag also has other effects. Change-Id: I9e41f4c567084cf30ed08f015a744959982940af Reviewed-on: https://boringssl-review.googlesource.com/30185 Reviewed-by: Matt Braithwaite <mab@google.com> |
||
---|---|---|
.. | ||
CMakeLists.txt | ||
ext_dat.h | ||
pcy_cache.c | ||
pcy_data.c | ||
pcy_int.h | ||
pcy_lib.c | ||
pcy_map.c | ||
pcy_node.c | ||
pcy_tree.c | ||
tab_test.cc | ||
v3_akey.c | ||
v3_akeya.c | ||
v3_alt.c | ||
v3_bcons.c | ||
v3_bitst.c | ||
v3_conf.c | ||
v3_cpols.c | ||
v3_crld.c | ||
v3_enum.c | ||
v3_extku.c | ||
v3_genn.c | ||
v3_ia5.c | ||
v3_info.c | ||
v3_int.c | ||
v3_lib.c | ||
v3_ncons.c | ||
v3_ocsp.c | ||
v3_pci.c | ||
v3_pcia.c | ||
v3_pcons.c | ||
v3_pku.c | ||
v3_pmaps.c | ||
v3_prn.c | ||
v3_purp.c | ||
v3_skey.c | ||
v3_sxnet.c | ||
v3_utl.c | ||
v3name_test.cc |