Hi Victor, On 12/11/17 4:18 PM, Viktor Dukhovni
wrote:
[...]I actually do not set anything but the flag in the verify parameter, that is (error checking removed for clarity): With this setting, I get the error.. which is the strange part as you said (the chain can not be longer :D). Maybe the code thinks that if you have a SubCA then you should have an additional level.. and since you do not have it, it sends the error... ??? Well.. considering the code structure, the flags should be ok (since I just set it and then use it right away...) ???... any suggestion on how to fix this ? Do you think it is actually a bug ? ... or am I missing some other configs / setting I should have done for the verify param ?You should obtain a reference to the existing parameters from the context, and modify these to add the new flag. Thanks, Max |
-- openssl-users mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users