The certificate hostname verification was not taking into account changes in
hostname due to a redirect which is handled via curl. I turned off the secapi hostname verification just allowing libcurls hostname verification, as it's better anyway (it handles alt names)meow-7.2.2
parent
61cb3d3113
commit
ca9737d6d6
|
|
@ -121,7 +121,10 @@ int secapiSSLCertVerifyCallback(X509_STORE_CTX *ctx, void *param)
|
|||
validation_params[CERT_HOSTNAME] = uri.hostName();
|
||||
try
|
||||
{
|
||||
chain->validate(VALIDATION_POLICY_SSL, store, validation_params);
|
||||
// we rely on libcurl to validate the hostname, as libcurl does more extensive validation
|
||||
// leaving our hostname validation call mechanism for future additions with respect to
|
||||
// OS native (Mac keyring, windows CAPI) validation.
|
||||
chain->validate(VALIDATION_POLICY_SSL & (~VALIDATION_POLICY_HOSTNAME), store, validation_params);
|
||||
}
|
||||
catch (LLCertValidationTrustException& cert_exception)
|
||||
{
|
||||
|
|
|
|||
Loading…
Reference in New Issue