CVSROOT: /cvs
Module name: src
Changes by: [email protected] 2026/09/24 04:52:31
Modified files:
usr.sbin/rpki-client: parser.c validate.c
Log message:
rpki-client: match CRLDP and referring Manifest for all !TA certs
Now that crl->mftcrldp is always set, we can move the comparison of
cert->crl with crl->mftdp into valid_x509() so that all certs which
come through here must satisfy this requirement. While TA certs are
not validated here, add a check for cert->purpose to avoid potential
NULL accesses.
ok job