[ 
https://issues.apache.org/jira/browse/PROTON-2976?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18121396#comment-18121396
 ] 

ASF subversion and git services commented on PROTON-2976:
---------------------------------------------------------

Commit d793f97e4a2d0f960eda32724a2e867236468337 in qpid-proton's branch 
refs/heads/main from Andrew Stitcher
[ https://gitbox.apache.org/repos/asf?p=qpid-proton.git;h=d793f97e4 ]

PROTON-2976: Make pn_ssl_domain_set_trusted_ca_db replace the default CAs

pn_ssl_domain_set_trusted_cs_db is using SSL_CTX_load_verify_locations(). This
loads the new CAs into the store that already holds the system certificates, so
adding to those CAs rather than overriding them.

Overriding is what the documentation has always described, and what SChannel
already does.

Install a fresh X509_STORE instead, in both the ssl and tls backends.

Assisted-By: Claude Opus 5 <[email protected]>


> pn_ssl_domain_set_trusted_ca_db should override default system trusted ca 
> roots
> -------------------------------------------------------------------------------
>
>                 Key: PROTON-2976
>                 URL: https://issues.apache.org/jira/browse/PROTON-2976
>             Project: Qpid Proton
>          Issue Type: Bug
>          Components: proton-c
>    Affects Versions: proton-c-0.28.0
>         Environment: Openssl
>            Reporter: Andrew Stitcher
>            Assignee: Andrew Stitcher
>            Priority: Major
>             Fix For: proton-c-0.41.0
>
>
> Instead of overriding the trusted certificate authorities as documented, the 
> openssl ssl/tls implementation adds the specified CAs to the existing system 
> default trust root.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to