« Previous | Next » 

Revision 4108c312

ID4108c31293b86f1323ec3d9012cfe8767ba78d00
Parent bd0d4581
Child 77715ede

Added by Tobias Müllerleile about 11 years ago

tls: Re-enable check of CN-ID in cert verification

RFC 6125 explicitly states that a client "MUST NOT seek a match
for a reference identifier of CN-ID if the presented identifiers
include a DNS-ID, SRV-ID, URI-ID, or any application-specific
identifier types supported by the client", but it MAY do so if
none of the mentioned identifier types (but others) are present.

Files

  • added
  • modified
  • copied
  • renamed
  • deleted

View differences