mirror of https://git.code.sf.net/p/isync/isync
Browse Source
we did not check a valid certificate's subject at all so far.
this is no problem if the certificate file contains only exactly the
wanted host's certificate - before revision 04fdf7d1
(dec 2000, < v0.4),
this was even enforced (more or less - if the peer cert had been
signed directly by a root cert, it would be accepted as well).
however, when the file contains root certificates (like the system-wide
certificate file typically does), any host with a valid certificate
could pretend to be the wanted host.
1.0
Oswald Buddenhagen
12 years ago
1 changed files with 68 additions and 7 deletions
Loading…
Reference in new issue