]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/commit
caroot: update CA bundle processor
authorKyle Evans <kevans@FreeBSD.org>
Tue, 30 Mar 2021 03:05:38 +0000 (22:05 -0500)
committerKyle Evans <kevans@FreeBSD.org>
Sat, 4 Sep 2021 07:39:00 +0000 (02:39 -0500)
commit0ef0442fcf63392502e4d2a645807a723562de0f
tree421b876503486ed154981ae38d8d6925e0355098
parent70d16ac0e889b88693d75c3541c6156355314124
caroot: update CA bundle processor

Our current processor was identified as trusting cert not explicitly
marked for SERVER_AUTH, as well as certs that were tagged with
DISTRUST_AFTER.

Update the script to handle both scenarios. This patch was originally
authored by mandree@ for ports, and it was subsequently ported to base
caroot.

(cherry picked from commit c3510c941c0dddd09389915a9395e6f059088bab)
secure/caroot/MAca-bundle.pl