Re: [Openvpn-devel] [PATCH v2] Use CryptoAPI to verify certificates

2007-01-04 Thread Faidon Liambotis
Alon Bar-Lev wrote: > If you integrate into Microsoft trust providers, you should also > support CTL and such. So that the Domain/Computer policy will be > applied to OpenVPN. After a bit of googling, I can know *guess* what you mean. I'm no Microsoft expert or developer -and I don't want to be, to

Re: [Openvpn-devel] [PATCH v2] Use CryptoAPI to verify certificates

2007-01-04 Thread Alon Bar-Lev
On 1/4/07, Faidon Liambotis wrote: Hi, Thank you for your comments. Alon Bar-Lev wrote: > On 1/3/07, Faidon Liambotis wrote: >> Ok, here's another try, even though I didn't get any comments on the >> first one :-) >> >> This is a totally different approach; the previous one was flawed in at >>

Re: [Openvpn-devel] [PATCH v2] Use CryptoAPI to verify certificates

2007-01-04 Thread Faidon Liambotis
Hi, Thank you for your comments. Alon Bar-Lev wrote: > On 1/3/07, Faidon Liambotis wrote: >> Ok, here's another try, even though I didn't get any comments on the >> first one :-) >> >> This is a totally different approach; the previous one was flawed in at >> least two aspects: > > This is bette

Re: [Openvpn-devel] [PATCH v2] Use CryptoAPI to verify certificates

2007-01-03 Thread Alon Bar-Lev
On 1/3/07, Faidon Liambotis wrote: Ok, here's another try, even though I didn't get any comments on the first one :-) This is a totally different approach; the previous one was flawed in at least two aspects: This is better. But you should use CertVerifyCertificateChainPolicy in order to veri