Working with sets of X.509 certificates

2013-03-10 Thread Ian Pilcher
This is a follow-up to my Trust *only* certs signed by an intermediate CA thread. I'm ready to try my hand at writing a validation callback function, and this function will need to somehow distinguish between two different sets of CA certificates -- validation-only CAs that are used only to

Actually supporting ipv6 literals in s_client?

2013-03-10 Thread Dan Mahoney, System Admin
Hey there, Apparently supporting ipv6 literals... like openssl s_client -connect '[2001:4f8:0:2::d]:443' ..in s_client is oft-asked for but never-implemented, to the point where there are blog articles like this out there: https://lwn.net/Articles/486369/, and most OSes that want to support