Commit 062ac11
Shigeki Ohtsu
crypto: add cert check to CNNIC Whitelist
When client connect to the server with certification issued by either
CNNIC Root CA or CNNIC EV Root CA, check hash of server
certification in the list of CNNICHashWhitelist.inc. If it's not,
CERT_REVOKED error returns.
See for details in
https://blog.mozilla.org/security/2015/04/02/distrusting-new-cnnic-certificates/1 parent 6d95f4f commit 062ac11
2 files changed
+5834
-1
lines changed
0 commit comments