]> git.ipfire.org Git - thirdparty/knot-resolver.git/commitdiff
daemon/tls: drop a DEBUG section
authorVladimír Čunát <vladimir.cunat@nic.cz>
Wed, 28 Aug 2024 11:28:02 +0000 (13:28 +0200)
committerVladimír Čunát <vladimir.cunat@nic.cz>
Mon, 2 Sep 2024 14:28:45 +0000 (16:28 +0200)
The new pin logging is better than this.  No need to recompile with -DDEBUG (rare).

daemon/tls.c

index b682285a2a16ca2ac4e55d84ac892bc41d680052..1aa24b299047e6f54dca2227ff386f26c3af4058 100644 (file)
@@ -775,20 +775,6 @@ static int client_verify_pin(const unsigned int cert_list_size,
                        return ret;
                }
 
-       #ifdef DEBUG
-               if (kr_log_is_debug(TLS, NULL)) {
-                       char pin_base64[TLS_SHA256_BASE64_BUFLEN];
-                       /* DEBUG: additionally compute and print the base64 pin.
-                        * Not very efficient, but that's OK for DEBUG. */
-                       ret = get_oob_key_pin(cert, pin_base64, sizeof(pin_base64), false);
-                       if (ret == GNUTLS_E_SUCCESS) {
-                               VERBOSE_MSG(true, "received pin: %s\n", pin_base64);
-                       } else {
-                               VERBOSE_MSG(true, "failed to convert received pin\n");
-                               /* Now we hope that `ret` below can't differ. */
-                       }
-               }
-       #endif
                char cert_pin[TLS_SHA256_RAW_LEN];
                /* Get raw pin and compare. */
                ret = get_oob_key_pin(cert, cert_pin, sizeof(cert_pin), true);