basic cleanups regarding SSL handling (#16940) [backport:1.0]
* basic cleanups regarding SSL handling * enabled certificate checking on Windows * updated the SSL test * quoting helps
This commit is contained in:
parent
f140c92409
commit
abac35e743
4 changed files with 59 additions and 18 deletions
|
|
@ -626,11 +626,13 @@ when defineSsl:
|
|||
discard newCTX.SSLCTXSetMode(SSL_MODE_AUTO_RETRY)
|
||||
newCTX.loadCertificates(certFile, keyFile)
|
||||
|
||||
when not defined(nimDisableCertificateValidation) and not defined(windows):
|
||||
const VerifySuccess = 1 # SSL_CTX_load_verify_locations returns 1 on success.
|
||||
|
||||
when not defined(nimDisableCertificateValidation):
|
||||
if verifyMode != CVerifyNone:
|
||||
# Use the caDir and caFile parameters if set
|
||||
if caDir != "" or caFile != "":
|
||||
if newCTX.SSL_CTX_load_verify_locations(caFile, caDir) != 0:
|
||||
if newCTX.SSL_CTX_load_verify_locations(caFile, caDir) != VerifySuccess:
|
||||
raise newException(IOError, "Failed to load SSL/TLS CA certificate(s).")
|
||||
|
||||
else:
|
||||
|
|
@ -638,7 +640,7 @@ when defineSsl:
|
|||
# the SSL_CERT_FILE and SSL_CERT_DIR env vars
|
||||
var found = false
|
||||
for fn in scanSSLCertificates():
|
||||
if newCTX.SSL_CTX_load_verify_locations(fn, "") == 0:
|
||||
if newCTX.SSL_CTX_load_verify_locations(fn, nil) == VerifySuccess:
|
||||
found = true
|
||||
break
|
||||
if not found:
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue