diff options
author | Martin Willi <martin@revosec.ch> | 2014-03-27 10:59:29 +0100 |
---|---|---|
committer | Martin Willi <martin@revosec.ch> | 2014-03-31 14:40:33 +0200 |
commit | a844b6589034ff53e845fb9013d69dac02385453 (patch) | |
tree | a4c18f3526bed498a0a14807b28c0739c08bc5e2 /scripts/crypt_burn.c | |
parent | efce234de43cd42c624b1ba62d37168c521a526e (diff) | |
download | strongswan-a844b6589034ff53e845fb9013d69dac02385453.tar.bz2 strongswan-a844b6589034ff53e845fb9013d69dac02385453.tar.xz |
revocation: Don't merge auth config of CLR/OCSP trustchain validation
This behavior was introduced with 6840a6fb to avoid key/signature strength
checking for the revocation trustchain as we do it for end entity certificates.
Unfortunately this breaks CA constraint checking under certain conditions, as
we merge additional intermediate/CA certificates to the auth config.
As key/signature strength checking of the revocation trustchain is a rather
exotic requirement we drop support for that to properly enforce CA constraints.
Diffstat (limited to 'scripts/crypt_burn.c')
0 files changed, 0 insertions, 0 deletions