Lee Clagett a3b0284837 Change SSL certificate file list to OpenSSL builtin load_verify_location
Specifying SSL certificates for peer verification does an exact match,
making it a not-so-obvious alias for the fingerprints option. This
changes the checks to OpenSSL which loads concatenated certificate(s)
from a single file and does a certificate-authority (chain of trust)
check instead. There is no drop in security - a compromised exact match
fingerprint has the same worse case failure. There is increased security
in allowing separate long-term CA key and short-term SSL server keys.

This also removes loading of the system-default CA files if a custom
CA file or certificate fingerprint is specified.
2019-04-06 23:47:06 -04:00
..
2018-09-04 13:19:58 -05:00
2019-04-06 16:00:18 +02:00
2019-03-05 22:05:34 +01:00
2014-03-03 22:07:58 +00:00
2019-03-05 22:05:34 +01:00
2014-03-03 22:07:58 +00:00
2019-03-05 22:05:34 +01:00
2019-01-22 20:30:51 +00:00
2014-03-03 22:07:58 +00:00
2014-03-03 22:07:58 +00:00
2015-01-02 18:52:46 +02:00
2019-03-31 18:39:25 +02:00
2015-01-02 18:52:46 +02:00
2015-01-02 18:52:46 +02:00
2019-03-05 22:05:34 +01:00