mirror of
https://github.com/yhirose/cpp-httplib.git
synced 2026-10-09 16:52:52 +07:00
Let the SSL chain policy alone judge the Windows chain (#2618)
verify_cert_with_windows_schannel() rejected a chain whenever TrustStatus.dwErrorStatus was non-zero, before CertVerifyCertificateChainPolicy() ran. The CERT_CHAIN_POLICY_IGNORE_ALL_REV_UNKNOWN_FLAGS flag passed to that policy check was therefore dead code: a certificate without revocation information, or one whose CRL could not be fetched, failed with CERT_TRUST_REVOCATION_STATUS_UNKNOWN. Drop the pre-check so the SSL chain policy is the only judge. Revocation checking becomes best-effort: a revoked certificate and every other chain error are still rejected, while an undetermined revocation status is accepted. On a rejected chain, ssl_backend_error() now holds the policy status, such as CERT_E_UNTRUSTEDROOT, instead of the trust status bit mask.
This commit is contained in:
+3
-5
@@ -14189,9 +14189,8 @@ TEST(SSLClientTest, WindowsCertificateVerification_ServerIntermediates_Online) {
|
||||
<< " ssl_backend_error=" << res.ssl_backend_error();
|
||||
}
|
||||
|
||||
// Windows, not the backend, decides on the chain: the error carries a
|
||||
// CryptoAPI trust status, which no backend error for a self-signed
|
||||
// certificate has.
|
||||
// Windows, not the backend, decides on the chain: the error is a CryptoAPI
|
||||
// policy status, which no backend reports for a self-signed certificate.
|
||||
TEST(SSLClientTest, WindowsCertificateVerification_RejectsUntrustedRoot) {
|
||||
SSLServer svr(SERVER_CERT2_FILE, SERVER_PRIVATE_KEY_FILE);
|
||||
ASSERT_TRUE(svr.is_valid());
|
||||
@@ -14211,8 +14210,7 @@ TEST(SSLClientTest, WindowsCertificateVerification_RejectsUntrustedRoot) {
|
||||
auto res = cli.Get("/");
|
||||
ASSERT_FALSE(res);
|
||||
EXPECT_EQ(Error::SSLServerVerification, res.error());
|
||||
EXPECT_NE(0u, res.ssl_backend_error() & CERT_TRUST_IS_UNTRUSTED_ROOT)
|
||||
<< "ssl_backend_error=" << res.ssl_backend_error();
|
||||
EXPECT_EQ(static_cast<DWORD>(CERT_E_UNTRUSTEDROOT), res.ssl_backend_error());
|
||||
}
|
||||
#endif
|
||||
|
||||
|
||||
Reference in New Issue
Block a user