]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/commit
caroot: update CA bundle processor
authorKyle Evans <kevans@FreeBSD.org>
Tue, 30 Mar 2021 03:05:38 +0000 (22:05 -0500)
committerKyle Evans <kevans@FreeBSD.org>
Tue, 13 Apr 2021 21:59:24 +0000 (16:59 -0500)
commitc3510c941c0dddd09389915a9395e6f059088bab
tree97806f19530278e7ede9f5c98bb486cdaf2f418a
parent446169e0b6f04b96960540784539c218f5a14c86
caroot: update CA bundle processor

Our current processor was identified as trusting cert not explicitly
marked for SERVER_AUTH, as well as certs that were tagged with
DISTRUST_AFTER.

Update the script to handle both scenarios. This patch was originally
authored by mandree@ for ports, and it was subsequently ported to base
caroot.

MFC after: 3 days
secure/caroot/MAca-bundle.pl