Re: [Openvpn-devel] OCSP_check.sh fixup

2014-09-25 Thread Steffan Karger
Hi Hubert, On 23-09-14 14:45, Hubert Kario wrote: > There are few serious issues with the OCSP_check.sh script: > 1. It will accept OCSP responses with bad signatures > 2. It may accept OCSP old responses as currently valid > > detailed description on bug tracker: > https://community.openvpn.ne

[Openvpn-devel] OCSP_check.sh fixup

2014-09-23 Thread Hubert Kario
There are few serious issues with the OCSP_check.sh script: 1. It will accept OCSP responses with bad signatures 2. It may accept OCSP old responses as currently valid detailed description on bug tracker: https://community.openvpn.net/openvpn/ticket/450#ticket Pull request with fixes: https://g