DANE/GnuTLS: split verification of mixed sets of TLSA records by usage
authorJeremy Harris <jgh146exb@wizmail.org>
Fri, 22 Dec 2017 17:19:37 +0000 (17:19 +0000)
committerJeremy Harris <jgh146exb@wizmail.org>
Fri, 22 Dec 2017 20:42:38 +0000 (20:42 +0000)
commit94c1328507098238ae5ec784150c1ae58f3b3118
tree33f9a1ecdf808459581ec9f5254cc5e5fd33ccb1
parent2b01e5359b79cfa9b31296700eb7fc5ae69162c5
DANE/GnuTLS: split verification of mixed sets of TLSA records by usage

This is because we cannot do the required CA-anchor and names checks for TA-mode
and not for EE-mode, without knowing which usage TLSA was used.
src/src/tls-gnu.c
test/dnszones-src/db.test.ex
test/log/5820
test/scripts/5820-DANE-GnuTLS/5820
test/stderr/5820
test/stdout/5820