Files
cpp-httplib/test
yhirose 75cc18b966 Pass the server's intermediates to Windows certificate verification
CryptoAPI got only the leaf, so it fetched an issuer from the leaf's AIA
URL instead of using the intermediates the server sent. For
accounts.spotify.com that issuer chains to Certainly Root R1, which
Windows does not trust, while the server's own chain ends at Starfield
Root G2.

Add tls::get_peer_certs(), which returns the certificates the peer sent
in the same way get_ca_certs() returns the CA certificates, for every
backend. The CryptoAPI check puts them into a memory store that it
passes to CertGetCertificateChain(). wolfSSL keeps the received chain
only when built with SESSION_CERTS; without it, CryptoAPI still gets the
leaf alone.

Refs #2596
2026-10-02 15:29:37 -04:00
..
…
…
…