Lee Clagett a3b0284837 Change SSL certificate file list to OpenSSL builtin load_verify_location
Specifying SSL certificates for peer verification does an exact match,
making it a not-so-obvious alias for the fingerprints option. This
changes the checks to OpenSSL which loads concatenated certificate(s)
from a single file and does a certificate-authority (chain of trust)
check instead. There is no drop in security - a compromised exact match
fingerprint has the same worse case failure. There is increased security
in allowing separate long-term CA key and short-term SSL server keys.

This also removes loading of the system-default CA files if a custom
CA file or certificate fingerprint is specified.
2019-04-06 23:47:06 -04:00
..
2019-03-05 22:05:34 +01:00
2019-03-05 22:05:34 +01:00
2017-11-03 11:27:50 -04:00
2016-12-04 20:12:40 +01:00
2015-01-02 18:52:46 +02:00
2015-01-02 18:52:46 +02:00
2015-01-02 18:52:46 +02:00
2015-01-02 18:52:46 +02:00
2015-01-02 18:52:46 +02:00
2015-01-02 18:52:46 +02:00