final SSL changes [backport:1.2] (#16983)
This commit is contained in:
parent
ceab5e49f2
commit
74d6a4d7f4
3 changed files with 30 additions and 8 deletions
|
|
@ -4,6 +4,13 @@
|
||||||
|
|
||||||
## Standard library additions and changes
|
## Standard library additions and changes
|
||||||
|
|
||||||
|
- On Windows the SSL library now checks for valid certificates.
|
||||||
|
It uses the `cacert.pem` file for this purpose which was extracted
|
||||||
|
from `https://curl.se/ca/cacert.pem`. Besides
|
||||||
|
the OpenSSL DLLs (e.g. libssl-1_1-x64.dll, libcrypto-1_1-x64.dll) you
|
||||||
|
now also need to ship `cacert.pem` with your `.exe` file.
|
||||||
|
|
||||||
|
|
||||||
- Make `{.requiresInit.}` pragma to work for `distinct` types.
|
- Make `{.requiresInit.}` pragma to work for `distinct` types.
|
||||||
|
|
||||||
- Added a macros `enumLen` for returning the number of items in an enum to the
|
- Added a macros `enumLen` for returning the number of items in an enum to the
|
||||||
|
|
|
||||||
|
|
@ -24,6 +24,17 @@
|
||||||
## `newContext<net.html#newContext%2Cstring%2Cstring%2Cstring%2Cstring>`_
|
## `newContext<net.html#newContext%2Cstring%2Cstring%2Cstring%2Cstring>`_
|
||||||
## procedure for additional details.
|
## procedure for additional details.
|
||||||
##
|
##
|
||||||
|
##
|
||||||
|
## SSL on Windows
|
||||||
|
## ==============
|
||||||
|
##
|
||||||
|
## On Windows the SSL library checks for valid certificates.
|
||||||
|
## It uses the `cacert.pem` file for this purpose which was extracted
|
||||||
|
## from `https://curl.se/ca/cacert.pem`. Besides
|
||||||
|
## the OpenSSL DLLs (e.g. libssl-1_1-x64.dll, libcrypto-1_1-x64.dll) you
|
||||||
|
## also need to ship `cacert.pem` with your `.exe` file.
|
||||||
|
##
|
||||||
|
##
|
||||||
## Examples
|
## Examples
|
||||||
## ========
|
## ========
|
||||||
##
|
##
|
||||||
|
|
|
||||||
|
|
@ -107,14 +107,18 @@ iterator scanSSLCertificates*(useEnvVars = false): string =
|
||||||
|
|
||||||
else:
|
else:
|
||||||
when defined(windows):
|
when defined(windows):
|
||||||
let pem = getAppDir() / "cacert.pem"
|
const cacert = "cacert.pem"
|
||||||
# We download the certificates according to https://curl.se/docs/caextract.html
|
let pem = getAppDir() / cacert
|
||||||
# These are the certificates from Firefox. The 'bitsadmin.exe' tool ships with every
|
if fileExists(pem):
|
||||||
# recent version of Windows (Windows 8, Windows XP, etc.)
|
|
||||||
if not fileExists(pem):
|
|
||||||
discard os.execShellCmd("""bitsadmin.exe /rawreturn /transfer "JobName" /priority FOREGROUND https://curl.se/ca/cacert.pem """ &
|
|
||||||
quoteShell(pem))
|
|
||||||
yield pem
|
yield pem
|
||||||
|
else:
|
||||||
|
let path = getEnv("PATH")
|
||||||
|
for candidate in split(path, PathSep):
|
||||||
|
if candidate.len != 0:
|
||||||
|
let x = (if candidate[0] == '"' and candidate[^1] == '"':
|
||||||
|
substr(candidate, 1, candidate.len-2) else: candidate) / cacert
|
||||||
|
if fileExists(x):
|
||||||
|
yield x
|
||||||
elif not defined(haiku):
|
elif not defined(haiku):
|
||||||
for p in certificatePaths:
|
for p in certificatePaths:
|
||||||
if p.endsWith(".pem") or p.endsWith(".crt"):
|
if p.endsWith(".pem") or p.endsWith(".crt"):
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue