RE: [RFC] OpenSSL accepts invalid server cert chain

2012-07-12 Thread Ryan Hurst
David, Failing when a server sends the certificates out of order would result in a large % of transactions failing. On platforms other than Windows the order is determined by the server administrator and what order they put them in the configuration. I recommend not changing the behavior

RE: [RFC] OpenSSL accepts invalid server cert chain

2012-07-12 Thread Erik Tkal
If the actual issuing CA is in your trust store and can be shown to have validly issued the server certificate, then by definition you trust that server. Erik Tkal Juniper OAC/UAC/Pulse Development -Original Message- From: