mirror of
https://github.com/yhirose/cpp-httplib.git
synced 2026-10-04 06:14:21 +07:00
Every backend loads the Windows ROOT and CA stores, but Windows adds a root to them only when CryptoAPI needs it to build a chain. On a machine that had not needed a root yet, the backend rejected the chain before the CryptoAPI check ran, so Windows never fetched the root (for example OpenSSL error 20 for accounts.spotify.com under Starfield Root G2). With Windows verification enabled, the backend's chain verdict is no longer used. Mbed TLS and wolfSSL skip chain verification during the handshake, and the post-handshake verify result is ignored. The CryptoAPI check becomes mandatory: a leaf that cannot be encoded now fails the connection instead of skipping the check, and the chain must allow server authentication, which the backends used to check. A server certificate verifier works on the backend's chain verification, so when one is set the backend still decides and CryptoAPI only adds its own check, as before. ClientCertMissing now disables hostname verification: cert.pem does not match HOST, and on Windows the hostname check fails before the chain check. Refs #2596