aboutsummaryrefslogtreecommitdiffstats
path: root/src/libcharon/plugins/attr_sql/attr_sql_plugin.c
diff options
context:
space:
mode:
authorTobias Brunner <tobias@strongswan.org>2014-12-18 09:13:38 +0100
committerTobias Brunner <tobias@strongswan.org>2015-03-06 16:49:12 +0100
commit6133770db4d827ee5834a96b81627875811c6eab (patch)
tree4b66c438ccbeed003135f78c21a28f568dc2e52f /src/libcharon/plugins/attr_sql/attr_sql_plugin.c
parent96e6130537df9d0388e73ba35e1984310b3a8653 (diff)
downloadstrongswan-6133770db4d827ee5834a96b81627875811c6eab.tar.bz2
strongswan-6133770db4d827ee5834a96b81627875811c6eab.tar.xz
x509: Use subjectKeyIdentifier provided by issuer cert when checking CRL issuer
Some CAs don't use SHA-1 hashes of the public key as subjectKeyIdentifier and authorityKeyIdentifier. If that's the case we can't force the calculation of the hash to compare that to authorityKeyIdentifier in the CRL, instead we use the subjectKeyIdentifier stored in the issuer certificate, if available. Otherwise, we fall back to the SHA-1 hash (or comparing the DNs) as before.
Diffstat (limited to 'src/libcharon/plugins/attr_sql/attr_sql_plugin.c')
0 files changed, 0 insertions, 0 deletions