]> git.ipfire.org Git - thirdparty/squid.git/commit
author: Alex Rousskov <rousskov@measurement-factory.com>
authorChristos Tsantilas <chtsanti@users.sourceforge.net>
Thu, 14 Aug 2014 08:54:49 +0000 (11:54 +0300)
committerChristos Tsantilas <chtsanti@users.sourceforge.net>
Thu, 14 Aug 2014 08:54:49 +0000 (11:54 +0300)
commit5c80eab204e660c5407052302dacabb805eade37
tree310b169aa9edbfb683188c1e8c94d14e0d2a3cda
parent02e1ed26125b25f3009636ea077bf876409a2052
author: Alex Rousskov <rousskov@measurement-factory.com>
Use v3 for fake certificate if we add _any_ certificate extension.

We used to force v3 version only when adding the subjectAltName extension.
That broke sites that did not have subjectAltName but used other mimicked x509
extensions, when accessed through Firefox 31 (at least):
https://bugzilla.mozilla.org/show_bug.cgi?id=1045973
src/ssl/gadgets.cc