summaryrefslogtreecommitdiff
path: root/lib/libcrypto/ec
diff options
context:
space:
mode:
authorTobias Heider <tobhe@cvs.openbsd.org>2022-07-04 09:23:16 +0000
committerTobias Heider <tobhe@cvs.openbsd.org>2022-07-04 09:23:16 +0000
commit1c88b6b1df617068afc47407344e14f07043b526 (patch)
tree95d297cf373710d026307bf2437babb65d3bc980 /lib/libcrypto/ec
parentb03f465924f3255dfb30a1306f0fc8505d533ec7 (diff)
Ignore any CERT payload after the first instead of failing the exchange
when more than one is received. The first CERT is always the leaf certificate, additional payloads can be used to send intermediate certs which iked can not handle at the moment. This fixes exchanges where the certificate chain is still valid because matching intermediate certs are available locally in /etc/iked. Reported and tested by Loïc Revest <l.revest (at) apc.fr> ok mbuhl@
Diffstat (limited to 'lib/libcrypto/ec')
0 files changed, 0 insertions, 0 deletions