Skip to content

Conversation

stoty
Copy link
Contributor

@stoty stoty commented Jul 7, 2025

  • Enable FIPS style server hostname verification if truststore is not specified
  • Make sure tcnative specific enableOCSP method is not called for JRE SSL provider
  • Add new config option to enable tcnative specific enableOCSP method
  • Add new config option to separetely enable certificate revocation checking for custom truststores
  • Add new config option to disable existing implicit certificate revocation checking logic for custom truststores
  • Document dependencies of TLS truststore related options

- Enable FIPS style server hostname verification if truststore is not specified
- Make sure tcnative specific enableOCSP method is not called for JRE SSL provider
- Add new config option to enable tcnative specific enableOCSP method
- Add new config option to separetely enable certificate revocation checking for custom truststores
- Add new config option to disable existing implicit certificate revocation checking logic for custom truststores
- Document dependencies of TLS truststore related options
@stoty
Copy link
Contributor Author

stoty commented Jul 7, 2025

#2276 is an improved version of this PR.

@stoty stoty closed this Jul 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant