summaryrefslogtreecommitdiff
path: root/src/lib/libcrypto/cversion.c
diff options
context:
space:
mode:
authorbeck <>2024-07-12 15:53:51 +0000
committerbeck <>2024-07-12 15:53:51 +0000
commit750dd2172e91324b076d0ea4d43b8c078293ae0b (patch)
tree8e28d8b6ee9d3035c3ea457cfb0551d4e86664cf /src/lib/libcrypto/cversion.c
parentf968d3012362bebc2f716ba82347226531c6f8ee (diff)
downloadopenbsd-750dd2172e91324b076d0ea4d43b8c078293ae0b.tar.gz
openbsd-750dd2172e91324b076d0ea4d43b8c078293ae0b.tar.bz2
openbsd-750dd2172e91324b076d0ea4d43b8c078293ae0b.zip
Clean up in X509_check_trust.
The XXX comment in here is now outdated. Our behaviour matches boringssl in that passing in a 0 trust gets the default behavior, which is to trust the certificate only if it has EKU any, or is self signed. Remove the goofy unused nid argument to "trust_compat" and rename it to what it really does, instead of some bizzare abstraction to something simple so the code need not change if we ever change our mind on what "compat" is for X.509, which will probably only happen when we are back to identifying things by something more sensible like recognizable grunts and smells. ok jsing@
Diffstat (limited to 'src/lib/libcrypto/cversion.c')
0 files changed, 0 insertions, 0 deletions