]> git.ipfire.org Git - thirdparty/apache/httpd.git/commit
[SECURITY] Don't stop Certificate Revoked messages.
authorWIND Internet <info@windinternet.nl>
Tue, 17 Mar 2020 21:04:15 +0000 (22:04 +0100)
committerWIND Internet <info@windinternet.nl>
Tue, 17 Mar 2020 21:04:15 +0000 (22:04 +0100)
commit7db9795f45fd4688ceb13ee36090e4e2becbc709
tree0d1d15577f2aa83120a1f446e73526b53dfe9a0d
parenta43f7c1f5af0280d46a3b068a7f2bae75374b80f
[SECURITY] Don't stop Certificate Revoked messages.

Certificate Revoked Responder messages don't belong to 'error' class.
When the server receives one, it MUST be passed on to the client.
And stored for the normal period of basic responses.

Also don't log an error each time it is retrieved from cache,
only once when it is retrieved from the OCSP responder.
modules/ssl/ssl_util_stapling.c