From 45ab3aef2dadee25e4a157de29b7b9c954d29ab4 Mon Sep 17 00:00:00 2001 From: Tatsuya Kinoshita Date: Sat, 13 Feb 2021 23:48:44 +0900 Subject: New patch 020_ssl-ca.patch to work ssl_ca_file and ssl_ca_path --- debian/patches/020_ssl-ca.patch | 14 ++++++++++++++ debian/patches/series | 1 + 2 files changed, 15 insertions(+) create mode 100644 debian/patches/020_ssl-ca.patch (limited to 'debian') diff --git a/debian/patches/020_ssl-ca.patch b/debian/patches/020_ssl-ca.patch new file mode 100644 index 0000000..9d2b834 --- /dev/null +++ b/debian/patches/020_ssl-ca.patch @@ -0,0 +1,14 @@ +Subject: Fix OpenSSL default always overrides ssl_ca_file and ssl_ca_path +Author: Tatsuya Kinoshita + +--- a/url.c ++++ b/url.c +@@ -445,7 +445,7 @@ openSSLHandle(int sock, char *hostname, char **p_cert) + } + } + if ((!ssl_ca_file && !ssl_ca_path) +- || SSL_CTX_load_verify_locations(ssl_ctx, ssl_ca_file, ssl_ca_path)) ++ || !SSL_CTX_load_verify_locations(ssl_ctx, ssl_ca_file, ssl_ca_path)) + #endif /* defined(USE_SSL_VERIFY) */ + SSL_CTX_set_default_verify_paths(ssl_ctx); + #endif /* SSLEAY_VERSION_NUMBER >= 0x0800 */ diff --git a/debian/patches/series b/debian/patches/series index e435bd4..ceb9913 100644 --- a/debian/patches/series +++ b/debian/patches/series @@ -1 +1,2 @@ 010_section.patch +020_ssl-ca.patch -- cgit v1.2.3