[openssl-dev] [openssl.org #4299] s_server cmd

Hubert Kario via RT rt at openssl.org
Tue Feb 9 15:26:11 UTC 2016


On Tuesday 09 February 2016 03:44:43 J Mohan Rao Arisankala via RT 
wrote:
>    - trusted_first option can be removed, as it is always enabled in
> 1.1.
> But not removed the option, require confirmation.

-trusted_first and the alternative chains (-no_alt_chains) work a bit 
differently so you can't say it is always enabled

in edge cases you will get different chains or validation failures 
depending on options set

-- 
Regards,
Hubert Kario
Senior Quality Engineer, QE BaseOS Security team
Web: www.cz.redhat.com
Red Hat Czech s.r.o., Purkyňova 99/71, 612 45, Brno, Czech Republic
-- 
Ticket here: http://rt.openssl.org/Ticket/Display.html?id=4299
Please log in as guest with password guest if prompted

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: not available
URL: <http://mta.openssl.org/pipermail/openssl-dev/attachments/20160209/6478f27c/attachment.sig>


More information about the openssl-dev mailing list