Page MenuHomePhabricator

Support "ssl.chain" in Aphlict configuration
ClosedPublic

Authored by epriestley on Apr 14 2016, 12:51 PM.
Tags
None
Referenced Files
F14057907: D15709.diff
Sun, Nov 17, 7:48 AM
F14045047: D15709.diff
Wed, Nov 13, 12:16 AM
F13994319: D15709.diff
Wed, Oct 23, 5:20 AM
F13991902: D15709.id.diff
Tue, Oct 22, 1:16 PM
F13991901: D15709.id37858.diff
Tue, Oct 22, 1:16 PM
F13991836: D15709.diff
Tue, Oct 22, 12:59 PM
F13989395: D15709.id.diff
Mon, Oct 21, 8:09 PM
F13989126: D15709.id.diff
Mon, Oct 21, 6:17 PM
Subscribers
None

Details

Summary

Fixes T10806. Although browsers don't seem to care about this, it's more correct to support it, and the new test console uses normal cURL and does care.

Test Plan
  • Hit the error case for providing a chain but no key/cert.
  • Used openssl s_client -connect localhost:22280 to connect to local Aphlict servers.
  • With SSL but no chain, saw openssl fail to verify the remote.
  • With SSL and a chain, saw openssl verify the identify of the remote.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable