]> git.ipfire.org Git - thirdparty/dovecot/core.git/commit
lib-master: Use ssl_require_crl setting only for server-side SSL settings
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Tue, 17 May 2022 10:31:40 +0000 (12:31 +0200)
committeraki.tuomi <aki.tuomi@open-xchange.com>
Thu, 24 Aug 2023 12:05:08 +0000 (12:05 +0000)
commit9f903ee8793a5f4513b5ad8c054a9a48bfffcd76
tree338329a476d23bb13e3c46df1173d2be22844a53
parent08528c38e187b03e26a3ba38283ef02059cf2122
lib-master: Use ssl_require_crl setting only for server-side SSL settings

We don't currently properly support checking CRLs when acting as SSL client.
The CRL would have to be stored as part of the CAs, which isn't commonly
done. This bug has been in the code ever since it was added in
30c5c1fc3608ae575f11960281d3e338b6bf7bc8, but it became more noticeable
with recent changes that started using lib-master for getting all SSL
client settings, e.g. 1e5324b5805bf7299cd8196f7b659fe935f027bd
src/lib-master/master-service-ssl-settings.c