Re: [exim/exim] [Bug]: GNUTLS certificate validation incompatible with certificates lacking a commonName attribute (Issue #3215)

Andreas Metzler via Exim-dev <[email protected]> Sun, 19 Apr 2026 14:07:52 +0200
Newsgroups gmane.mail.exim.devel
Message-ID <[email protected]>
On 2026-04-19 Jeremy Harris via Exim-dev <[email protected]> wrote:
> > > On Sat, Apr 18, 2026 at 06:25:00PM +0200, Andreas Metzler via Exim-dev wrote:
> > 
> > > > In my tests gnutls_x509_crt_get_dn() returned
> > > > GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE for Adam's test-host instead of 0.
> Thanks for testing, Andreas.  So, allowing for both the error return
> and a zero return:

[...]

Thanks, this gives the expected ...

13:56:16 105918 TLS: checking peer certificate
13:56:16 105918 GnuTLS<3>: ASSERT: ../../../lib/x509/dn.c[_gnutls_x509_get_dn]:221
13:56:16 105918 GnuTLS<3>: ASSERT: ../../../lib/x509/dn.c[_gnutls_x509_parse_dn]:279
13:56:16 105918 TLS: no DN
[...]
13:56:16 105918 GnuTLS<3>: ASSERT: ../../../lib/x509/name_constraints.c[gnutls_x509_crt_get_name_constraints]:1041
13:56:16 105918 TLS certificate verified: peerdn=""

cu Andreas
-- 
"You people are noisy," Nia said.
I made the gesture of agreement.