Using default CA path from openssl

Philipp e1c1bac6253dc54a1e89ddc046585792 at posteo.net
Thu Sep 11 03:14:58 UTC 2014


Am 11.09.2014 00:56 schrieb Michal Cichra:
> What I propose is a configuration flag, to set
> `SSL_CTX_set_default_verify_paths`.

Careful what you wish for..

I didnt check the surrounding code, but above call and CAfile/CApath 
sets (if cmd-line or via API wont matter)
has "funny" error conditions; see this post and the thread:
http://marc.info/?l=openbsd-tech&m=140646297120492&w=2

Just a 2ct heads up.



More information about the nginx mailing list