CVSROOT: /cvs Module name: src Changes by: [email protected] 2024/06/06 05:53:09
Modified files:
usr.sbin/rpki-client: cert.c
Log message:
Check that TA certs are correctly signed
We know the pubkey from the TAL, so check that the signature is right
as required by RFC 6487, section 7, additional condition 1, applied to
self-issued certs. Make the error check weird since OpenSSL 3 broke yet
another API (thanks claudio for making me go look).
ok claudio job
