Commit 3bd9765
committed
Fix strict client chain check with TLS-1.3
When TLS-1.3 is used and the server does not send any CA names
the ca_dn will be NULL. sk_X509_NAME_num() returns -1 on null
argument.
Reviewed-by: Todd Short <[email protected]>
Reviewed-by: Matt Caswell <[email protected]>
(Merged from openssl#17986)
(cherry picked from commit 89dd854)1 parent b7ce611 commit 3bd9765
1 file changed
+6
-8
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2369 | 2369 | | |
2370 | 2370 | | |
2371 | 2371 | | |
2372 | | - | |
| 2372 | + | |
| 2373 | + | |
| 2374 | + | |
2373 | 2375 | | |
2374 | | - | |
2375 | | - | |
2376 | | - | |
2377 | | - | |
2378 | | - | |
2379 | | - | |
| 2376 | + | |
2380 | 2377 | | |
2381 | 2378 | | |
| 2379 | + | |
2382 | 2380 | | |
2383 | 2381 | | |
2384 | 2382 | | |
2385 | 2383 | | |
2386 | 2384 | | |
2387 | | - | |
| 2385 | + | |
2388 | 2386 | | |
2389 | 2387 | | |
2390 | 2388 | | |
| |||
0 commit comments