Re: [exim/exim] [Bug]: GNUTLS certificate validation incompatible with certificates lacking a commonName attribute (Issue #3215)
Viktor Dukhovni via Exim-dev <[email protected]> Sun, 19 Apr 2026 13:08:37 +1000
| Newsgroups | gmane.mail.exim.devel |
|---|---|
| Message-ID | <[email protected]> |
On Sat, Apr 18, 2026 at 06:25:00PM +0200, Andreas Metzler via Exim-dev wrote:
> In my tests gnutls_x509_crt_get_dn() returned
> GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE for Adam's test-host instead of 0.
> Which matches the docs:
> https://gnutls.org/reference/gnutls-x509.html#gnutls-x509-crt-get-dn
The documentation is also in a state of sin, describing a fictional
situation in which "the DN does not exist", as opposed to "the DN
is an empty sequence". In your tests, did you pass a NULL for the
output buffer and a pointer to a size that was initialised to 0?
--
Viktor. 🇺🇦 Слава Україні!
--
## subscription configuration (requires account):
## https://lists.exim.org/mailman3/postorius/lists/exim-dev.lists.exim.org/
## unsubscribe (doesn't require an account):
## [email protected]
## Exim details at https://www.exim.org/
## Please use the Wiki with this list - https://code.exim.org/exim/wiki/wiki