mirror of
https://github.com/yhirose/cpp-httplib.git
synced 2026-10-03 14:03:15 +07:00
CryptoAPI got only the leaf, so it fetched an issuer from the leaf's AIA URL instead of using the intermediates the server sent. For accounts.spotify.com that issuer chains to Certainly Root R1, which Windows does not trust, while the server's own chain ends at Starfield Root G2. Add tls::get_peer_certs(), which returns the certificates the peer sent in the same way get_ca_certs() returns the CA certificates, for every backend. The CryptoAPI check puts them into a memory store that it passes to CertGetCertificateChain(). wolfSSL keeps the received chain only when built with SESSION_CERTS; without it, CryptoAPI still gets the leaf alone. Refs #2596