1
0

0001-S2S-SSL-GnuTLS-Enable-CRL-verification_26.1.patch 736 B

123456789101112131415161718192021
  1. From edb8fce8719efb0d887c72495e540d60a3bf4ed7 Mon Sep 17 00:00:00 2001
  2. From: Christoph Biedl <ngircd.anoy@manchmal.in-ulm.de>
  3. Date: Sun, 31 Mar 2024 00:36:53 +0100
  4. Subject: [PATCH] S2S-SSL/GnuTLS: Enable CRL verification
  5. (cherry picked from commit b2c9049af20b12f2fde08f4af0a35968404effdb)
  6. ---
  7. src/ngircd/conn-ssl.c | 2 ++
  8. 1 file changed, 2 insertions(+)
  9. --- a/src/ngircd/conn-ssl.c
  10. +++ b/src/ngircd/conn-ssl.c
  11. @@ -486,6 +486,8 @@
  12. return false;
  13. gnutls_certificate_set_dh_params(x509_cred, dh_params);
  14. + gnutls_certificate_set_flags(x509_cred, GNUTLS_CERTIFICATE_VERIFY_CRLS);
  15. +
  16. err = gnutls_certificate_set_x509_key_file(x509_cred, cert_file, Conf_SSLOptions.KeyFile, GNUTLS_X509_FMT_PEM);
  17. if (err < 0) {
  18. Log(LOG_ERR,