[openssl-dev] [openssl.org #1210] Bug: CRL and Certificates

Rich Salz via RT rt at openssl.org
Tue Feb 2 19:30:32 UTC 2016


Re-thinking about this a bit more, OpenSSL doesn't do any key-usage
verification of things when it does signatures.
So I am closing this ticket.
As a work-around, verifying the signature and usage of the signed data maybe?
(If someone wants to do a PR to fix this, great.)
--
Rich Salz, OpenSSL dev team; rsalz at openssl.org



More information about the openssl-dev mailing list