]> git.ipfire.org Git - thirdparty/hostap.git/commitdiff
wolfSSL: Fix OCSP stapling
authorJuliusz Sosinowicz <juliusz@wolfssl.com>
Mon, 25 Apr 2022 14:18:49 +0000 (16:18 +0200)
committerJouni Malinen <j@w1.fi>
Sun, 1 May 2022 14:27:04 +0000 (17:27 +0300)
Signed-off-by: Juliusz Sosinowicz <juliusz@wolfssl.com>
src/crypto/tls_wolfssl.c

index 5dccfe6dd164470cdadb2cd16da50cc5c725297f..b4f1bbe7f72ebbdd3ef242192bd04be0073c0b91 100644 (file)
@@ -1339,7 +1339,8 @@ int tls_connection_set_params(void *tls_ctx, struct tls_connection *conn,
                                            WOLFSSL_CSR_OCSP_USE_NONCE) !=
                    SSL_SUCCESS)
                        return -1;
-               wolfSSL_CTX_EnableOCSP(tls_ctx, 0);
+               if (wolfSSL_EnableOCSPStapling(conn->ssl) != SSL_SUCCESS)
+                       return -1;
        }
 #endif /* HAVE_CERTIFICATE_STATUS_REQUEST */
 #ifdef HAVE_CERTIFICATE_STATUS_REQUEST_V2
@@ -1348,7 +1349,8 @@ int tls_connection_set_params(void *tls_ctx, struct tls_connection *conn,
                                              WOLFSSL_CSR2_OCSP_MULTI, 0) !=
                    SSL_SUCCESS)
                        return -1;
-               wolfSSL_CTX_EnableOCSP(tls_ctx, 0);
+               if (wolfSSL_EnableOCSPStapling(conn->ssl) != SSL_SUCCESS)
+                       return -1;
        }
 #endif /* HAVE_CERTIFICATE_STATUS_REQUEST_V2 */
 #if !defined(HAVE_CERTIFICATE_STATUS_REQUEST) && \