Re: GnuTLS | [#1893] Align max cert verify depth with OpenSSL (!2122)

"\(Deprecated\) Read-only notification of GnuTLS library development activities" <[email protected]>
Newsgroups gmane.comp.encryption.gpg.gnutls.devel
Message-ID <[email protected]>


Tim Rühsen started a new discussion on lib/gnutls_int.h: https://gitlab.com/gnutls/gnutls/-/merge_requests/2122#note_3662766930

 >   * update many_icas in tests/test-chains.h when increasing
 >   * DEFAULT_MAX_VERIFY_DEPTH.
 >   */
 > -#define DEFAULT_MAX_VERIFY_DEPTH 16
 >  #define DEFAULT_MAX_VERIFY_BITS (MAX_PK_PARAM_SIZE * 8)
 >  #define MAX_VERIFY_DEPTH 4096
 >  
 > +/* The depth includes the peer certificate, unlike OpenSSL's limit. */

Confusing: The title says "align with OpenSSL", but here the comment says "unlike OpenSSL's limit".

-- 
Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2122#note_3662766930
You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/6-a8cjw105exrzmbxmdmyud5tpz-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help

_______________________________________________
Gnutls-devel mailing list
[email protected]
http://lists.gnupg.org/mailman/listinfo/gnutls-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.