> Le 31 mars 2020 à 18:40, William Lallemand <wlallem...@haproxy.com> a écrit : > > On Thu, Mar 26, 2020 at 06:29:48PM +0100, William Lallemand wrote: >> >> After some thinking and discussing with people involved in this part of >> HAProxy. I'm not feeling very confortable with setting this behavior by >> default, on top on that the next version is an LTS so its not a good >> idea to change this behavior yet. I think in most case it won't be a >> problem but it would be better if it's enabled by an option in the >> global section. >> > > Hi Manu, > > Could you take a look at this? Because I already merged your first > patch, so if we don't do anything about it we may revert it before the > release. > > Thanks a lot!
Hi William, It’s really safe because self Issued CA is the X509 end chain by definition, but yes it change the behaviour. Why not an option in global section. ++ Manu