From: Alan T. DeKok Date: Thu, 10 Dec 2015 20:28:45 +0000 (-0500) Subject: Copy TLS cert VPs to request, even on fail. X-Git-Tag: release_3_0_11~91 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=c157da82eba355d30e371146124f5e4548070a26;p=thirdparty%2Ffreeradius-server.git Copy TLS cert VPs to request, even on fail. This lets you log *why* it failed, and for who --- diff --git a/src/main/tls.c b/src/main/tls.c index 5d2af7edc7d..254e4d51217 100644 --- a/src/main/tls.c +++ b/src/main/tls.c @@ -2150,10 +2150,12 @@ int cbtls_verify(int ok, X509_STORE_CTX *ctx) unlink(filename); break; } - - } /* depth == 0 */ + if (certs && request && !my_ok) { + fr_pair_add(&request->packet->vps, fr_pair_list_copy(request->packet, *certs)); + } + if (RDEBUG_ENABLED3) { RDEBUG3("chain-depth : %d", depth); RDEBUG3("error : %d", err);