From 0e84a3939e912f6a384416b3af214fe8d44ff343 Mon Sep 17 00:00:00 2001 From: jsing <> Date: Mon, 14 Sep 2015 16:16:38 +0000 Subject: Provide tls_config_insecure_noverifytime() in order to be able to disable certificate validity checking. ok beck@ --- src/lib/libtls/tls.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) (limited to 'src/lib/libtls/tls.c') diff --git a/src/lib/libtls/tls.c b/src/lib/libtls/tls.c index 236ed9185b..ac9262a4fc 100644 --- a/src/lib/libtls/tls.c +++ b/src/lib/libtls/tls.c @@ -1,4 +1,4 @@ -/* $OpenBSD: tls.c,v 1.31 2015/09/14 12:29:16 jsing Exp $ */ +/* $OpenBSD: tls.c,v 1.32 2015/09/14 16:16:38 jsing Exp $ */ /* * Copyright (c) 2014 Joel Sing * @@ -257,6 +257,11 @@ tls_configure_ssl(struct tls *ctx) } } + if (ctx->config->verify_time == 0) { + X509_VERIFY_PARAM_set_flags(ctx->ssl_ctx->param, + X509_V_FLAG_NO_CHECK_TIME); + } + return (0); err: -- cgit v1.2.3-55-g6feb