Commit 89dd854
committed
Fix strict client chain check with TLS-1.3
When TLS-1.3 is used and the server does not send any CA names
the ca_dn will be NULL. sk_X509_NAME_num() returns -1 on null
argument.
Reviewed-by: Todd Short <[email protected]>
Reviewed-by: Matt Caswell <[email protected]>
(Merged from openssl#17986)1 parent 336d92e commit 89dd854
1 file changed
+6
-8
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2870 | 2870 | | |
2871 | 2871 | | |
2872 | 2872 | | |
2873 | | - | |
| 2873 | + | |
| 2874 | + | |
| 2875 | + | |
2874 | 2876 | | |
2875 | | - | |
2876 | | - | |
2877 | | - | |
2878 | | - | |
2879 | | - | |
2880 | | - | |
| 2877 | + | |
2881 | 2878 | | |
2882 | 2879 | | |
| 2880 | + | |
2883 | 2881 | | |
2884 | 2882 | | |
2885 | 2883 | | |
2886 | 2884 | | |
2887 | 2885 | | |
2888 | | - | |
| 2886 | + | |
2889 | 2887 | | |
2890 | 2888 | | |
2891 | 2889 | | |
| |||
0 commit comments