DANE/GnuTLS: ignore traditional CA anchor validation in DANE-EE mode
authorJeremy Harris <jgh146exb@wizmail.org>
Wed, 20 Dec 2017 21:14:06 +0000 (21:14 +0000)
committerJeremy Harris <jgh146exb@wizmail.org>
Wed, 20 Dec 2017 22:03:23 +0000 (22:03 +0000)
commit28646fa9c74b94722eadd7bc2d9c285245aded80
tree213e769b061562eb002237306a5da80b70c56d0c
parent944e8b37e80589aef9de20ea5fedd98bc0900307
DANE/GnuTLS: ignore traditional CA anchor validation in DANE-EE mode

Not quite right for a mixed TA+EE set of TLSA records, but better than always-enforcing
12 files changed:
src/src/tls-gnu.c
test/confs/5820
test/confs/5840
test/dnszones-src/db.example.com
test/log/5820
test/log/5840
test/scripts/5820-DANE-GnuTLS/5820
test/scripts/5840-DANE-OpenSSL/5840
test/stderr/5820
test/stderr/5840
test/stdout/5820
test/stdout/5840