[openssl-dev] [openssl.org #4644] bug: cert verification always examining entire chain

Viktor Dukhovni openssl-users at dukhovni.org
Tue Aug 9 15:28:20 UTC 2016


On Tue, Aug 09, 2016 at 10:53:59AM +0100, David Woodhouse wrote:

> > As expected, unless you use the "-partial" flag in the command-line
> > utilities, or use the X509_VERIFY_PARAM_set_flags() to set the
> > X509_V_FLAG_PARTIAL_CHAIN flag when using the API.
> 
> Is there an equivalent for 1.0.1?

None that I'm aware of, partial chain support was added in 1.0.2.

--
	Viktor.


More information about the openssl-dev mailing list