Github user laurentgo commented on a diff in the pull request:

    https://github.com/apache/drill/pull/950#discussion_r142993025
  
    --- Diff: contrib/native/client/src/clientlib/wincert.ipp ---
    @@ -0,0 +1,98 @@
    +/*
    + * Licensed to the Apache Software Foundation (ASF) under one
    + * or more contributor license agreements.  See the NOTICE file
    + * distributed with this work for additional information
    + * regarding copyright ownership.  The ASF licenses this file
    + * to you under the Apache License, Version 2.0 (the
    + * "License"); you may not use this file except in compliance
    + * with the License.  You may obtain a copy of the License at
    + *
    + * http://www.apache.org/licenses/LICENSE-2.0
    + *
    + * Unless required by applicable law or agreed to in writing, software
    + * distributed under the License is distributed on an "AS IS" BASIS,
    + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
    + * See the License for the specific language governing permissions and
    + * limitations under the License.
    + */
    +
    +#if defined(IS_SSL_ENABLED)
    +
    +#include <openssl/x509.h>
    +#include <openssl/ssl.h>
    +
    +#if defined _WIN32  || defined _WIN64
    +
    +#include <stdio.h>
    +#include <windows.h>
    +#include <wincrypt.h>
    +#include <cryptuiapi.h>
    +#include <iostream>
    +#include <tchar.h>
    +
    +
    +#pragma comment (lib, "crypt32.lib")
    +#pragma comment (lib, "cryptui.lib")
    +
    +#define MY_ENCODING_TYPE  (PKCS_7_ASN_ENCODING | X509_ASN_ENCODING)
    +
    +inline
    +int loadSystemTrustStore(const SSL *ssl, std::string& msg) {
    --- End diff --
    
    it looks like boost::asio support both loading a file and/or a verify 
callback:
    - 
http://www.boost.org/doc/libs/1_47_0/doc/html/boost_asio/reference/ssl__context/set_verify_callback/overload1.html
    - 
http://www.boost.org/doc/libs/1_47_0/doc/html/boost_asio/reference/ssl__context/load_verify_file.html
    
    It seems you wouldn't even need to access the native handle when using 
these functions


---

Reply via email to