aboutsummaryrefslogtreecommitdiffstats
path: root/g10/parse-packet.c
diff options
context:
space:
mode:
authorWerner Koch <[email protected]>2014-06-02 14:02:30 +0000
committerWerner Koch <[email protected]>2014-06-02 14:02:30 +0000
commit715285bcbc12c024dbd9b633805189c09173e317 (patch)
tree356c68ab80645d1913da107a2785fbd1d48612e6 /g10/parse-packet.c
parentgpgsm: Add a way to save a found state. (diff)
downloadgnupg-715285bcbc12c024dbd9b633805189c09173e317.tar.gz
gnupg-715285bcbc12c024dbd9b633805189c09173e317.zip
gpgsm: Handle re-issued CA certificates in a better way.
* sm/certchain.c (find_up_search_by_keyid): Consider all matching certificates. (find_up): Add some debug messages. -- The DFN-Verein recently re-issued its CA certificates without generating new keys. Thus looking up the chain using the authority keyids works but may use still existing old certificates. This may break the CRL lookup in the Dirmngr. The hack to fix this is by using the latest issued certificate with the same subject key identifier. As usual Peter Gutman's X.509 style guide has some comments on that re-issuing. GnuPG-bug-id: 1644
Diffstat (limited to 'g10/parse-packet.c')
0 files changed, 0 insertions, 0 deletions