Re: [exim/exim] [Bug]: GNUTLS certificate validation incompatible with certificates lacking a commonName attribute (Issue #3215)
Andreas Metzler via Exim-dev <[email protected]> Sun, 19 Apr 2026 14:07:52 +0200
| Newsgroups | gmane.mail.exim.devel |
|---|---|
| Message-ID | <[email protected]> |
On 2026-04-19 Jeremy Harris via Exim-dev <[email protected]> wrote: > > > On Sat, Apr 18, 2026 at 06:25:00PM +0200, Andreas Metzler via Exim-dev wrote: > > > > > > In my tests gnutls_x509_crt_get_dn() returned > > > > GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE for Adam's test-host instead of 0. > Thanks for testing, Andreas. So, allowing for both the error return > and a zero return: [...] Thanks, this gives the expected ... 13:56:16 105918 TLS: checking peer certificate 13:56:16 105918 GnuTLS<3>: ASSERT: ../../../lib/x509/dn.c[_gnutls_x509_get_dn]:221 13:56:16 105918 GnuTLS<3>: ASSERT: ../../../lib/x509/dn.c[_gnutls_x509_parse_dn]:279 13:56:16 105918 TLS: no DN [...] 13:56:16 105918 GnuTLS<3>: ASSERT: ../../../lib/x509/name_constraints.c[gnutls_x509_crt_get_name_constraints]:1041 13:56:16 105918 TLS certificate verified: peerdn="" cu Andreas -- "You people are noisy," Nia said. I made the gesture of agreement.