[w3m-dev 04050] SSL verify

* url.c (openSSLHandle): don't load verify locations if
	both ssl_ca_file and ssl_ca_path is NULL.
From: AIDA Shinra <shinra@j10n.org>
This commit is contained in:
Fumitoshi UKAI
2004-03-30 18:06:42 +00:00
parent f8ca559c64
commit b5bb094440
2 changed files with 10 additions and 3 deletions

5
url.c
View File

@@ -1,4 +1,4 @@
/* $Id: url.c,v 1.87 2003/12/08 16:17:21 ukai Exp $ */
/* $Id: url.c,v 1.88 2004/03/30 18:06:43 ukai Exp $ */
#include "fm.h"
#include <sys/types.h>
#include <sys/socket.h>
@@ -354,7 +354,8 @@ openSSLHandle(int sock, char *hostname, char **p_cert)
goto eend;
}
}
if (SSL_CTX_load_verify_locations(ssl_ctx, ssl_ca_file, ssl_ca_path))
if ((!ssl_ca_file && !ssl_ca_path)
|| SSL_CTX_load_verify_locations(ssl_ctx, ssl_ca_file, ssl_ca_path))
#endif /* defined(USE_SSL_VERIFY) */
SSL_CTX_set_default_verify_paths(ssl_ctx);
#endif /* SSLEAY_VERSION_NUMBER >= 0x0800 */