[openssl.org #1942] [PATCH] ssl3_output_cert_chain() selects wrong certificate as issuer.

2009-06-28 Thread Stephen Henson via RT
[dw...@infradead.org - Tue Jun 02 15:21:30 2009]: On Tue, 2009-06-02 at 13:40 +0200, Stephen Henson via RT wrote: If however we are going to revise this I'd say we should use X509_verify_cert to build the chain instead of more ad-hoc stuff. This seems to work... only tested for

[openssl.org #1960] i2d_SSL_SESSION/d2i_SSL_SESSION does not persist session compress_meth

2009-06-28 Thread Stephen Henson via RT
[sean.cunning...@mandiant.com - Thu Jun 25 08:23:49 2009]: This bug is not platform specific. Some proxies, such as nginx, implement custom session caches via the openssl callback API's. This implementation makes use of the i2d_SSL_SESSION API to copy the session into a