summaryrefslogtreecommitdiff
path: root/lib/stream-ssl.c
diff options
context:
space:
mode:
authorBen Pfaff <blp@nicira.com>2011-06-15 11:50:24 -0700
committerBen Pfaff <blp@nicira.com>2011-06-17 10:50:23 -0700
commite6a8ca62a6ae32285b1c6a668f35159be72199d3 (patch)
tree52085603431d6cdbb9fe87d4f03a19be66cebbc8 /lib/stream-ssl.c
parent7211b387b752ce2c67f1aee639bccc8bd0500c48 (diff)
downloadopenvswitch-e6a8ca62a6ae32285b1c6a668f35159be72199d3.tar.gz
stream-ssl: Clear CAs for certificate verification before adding new ones.
If the CA certificate changed and OVS added the new CA certificate, the change was ineffective. Clearing the certificate store before adding the new CA certificate fixes the problem. I don't know exactly why this fixes the problem, but in my testing it does. Bug #2921. Reported-by: Dan Wendlandt <dan@nicira.com> Reported-by: Pierre Ettori <pettori@nicira.com>
Diffstat (limited to 'lib/stream-ssl.c')
-rw-r--r--lib/stream-ssl.c2
1 files changed, 2 insertions, 0 deletions
diff --git a/lib/stream-ssl.c b/lib/stream-ssl.c
index 4d7c7c4dd..e68cc72bc 100644
--- a/lib/stream-ssl.c
+++ b/lib/stream-ssl.c
@@ -413,6 +413,7 @@ do_ca_cert_bootstrap(struct stream *stream)
if (!cert) {
out_of_memory();
}
+ SSL_CTX_set_cert_store(ctx, X509_STORE_new());
if (SSL_CTX_load_verify_locations(ctx, ca_cert.file_name, NULL) != 1) {
VLOG_ERR("SSL_CTX_load_verify_locations: %s",
ERR_error_string(ERR_get_error(), NULL));
@@ -1215,6 +1216,7 @@ stream_ssl_set_ca_cert_file__(const char *file_name,
/* Set up CAs for OpenSSL to trust in verifying the peer's
* certificate. */
+ SSL_CTX_set_cert_store(ctx, X509_STORE_new());
if (SSL_CTX_load_verify_locations(ctx, file_name, NULL) != 1) {
VLOG_ERR("SSL_CTX_load_verify_locations: %s",
ERR_error_string(ERR_get_error(), NULL));