mirror of
https://github.com/yhirose/cpp-httplib.git
synced 2026-10-04 06:14:21 +07:00
Pass the server's intermediates to Windows certificate verification
CryptoAPI got only the leaf, so it fetched an issuer from the leaf's AIA URL instead of using the intermediates the server sent. For accounts.spotify.com that issuer chains to Certainly Root R1, which Windows does not trust, while the server's own chain ends at Starfield Root G2. Add tls::get_peer_certs(), which returns the certificates the peer sent in the same way get_ca_certs() returns the CA certificates, for every backend. The CryptoAPI check puts them into a memory store that it passes to CertGetCertificateChain(). wolfSSL keeps the received chain only when built with SESSION_CERTS; without it, CryptoAPI still gets the leaf alone. Refs #2596
This commit is contained in:
@@ -13958,6 +13958,15 @@ TEST(SSLClientTest, WindowsCertificateVerification_Disabled) {
|
||||
auto res = cli.Get("/");
|
||||
if (res) { EXPECT_NE(StatusCode::InternalServerError_500, res->status); }
|
||||
}
|
||||
|
||||
// The server sends an intermediate cross-signed by a root Windows trusts,
|
||||
// while the leaf's AIA URL leads to one under a root Windows does not trust.
|
||||
TEST(SSLClientTest, WindowsCertificateVerification_ServerIntermediates_Online) {
|
||||
SSLClient cli("accounts.spotify.com", 443);
|
||||
auto res = cli.Get("/");
|
||||
ASSERT_TRUE(res) << "Error: " << to_string(res.error())
|
||||
<< " ssl_backend_error=" << res.ssl_backend_error();
|
||||
}
|
||||
#endif
|
||||
|
||||
TEST(SSLClientTest, ServerCertificateVerification1_Online) {
|
||||
|
||||
Reference in New Issue
Block a user