diff options
| author | Ben Pfaff <blp@nicira.com> | 2011-06-15 11:50:24 -0700 |
|---|---|---|
| committer | Ben Pfaff <blp@nicira.com> | 2011-06-17 10:50:23 -0700 |
| commit | e6a8ca62a6ae32285b1c6a668f35159be72199d3 (patch) | |
| tree | 52085603431d6cdbb9fe87d4f03a19be66cebbc8 /lib/stream-ssl.c | |
| parent | 7211b387b752ce2c67f1aee639bccc8bd0500c48 (diff) | |
| download | openvswitch-e6a8ca62a6ae32285b1c6a668f35159be72199d3.tar.gz | |
stream-ssl: Clear CAs for certificate verification before adding new ones.
If the CA certificate changed and OVS added the new CA certificate, the
change was ineffective. Clearing the certificate store before adding the
new CA certificate fixes the problem.
I don't know exactly why this fixes the problem, but in my testing it does.
Bug #2921.
Reported-by: Dan Wendlandt <dan@nicira.com>
Reported-by: Pierre Ettori <pettori@nicira.com>
Diffstat (limited to 'lib/stream-ssl.c')
| -rw-r--r-- | lib/stream-ssl.c | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/lib/stream-ssl.c b/lib/stream-ssl.c index 4d7c7c4dd..e68cc72bc 100644 --- a/lib/stream-ssl.c +++ b/lib/stream-ssl.c @@ -413,6 +413,7 @@ do_ca_cert_bootstrap(struct stream *stream) if (!cert) { out_of_memory(); } + SSL_CTX_set_cert_store(ctx, X509_STORE_new()); if (SSL_CTX_load_verify_locations(ctx, ca_cert.file_name, NULL) != 1) { VLOG_ERR("SSL_CTX_load_verify_locations: %s", ERR_error_string(ERR_get_error(), NULL)); @@ -1215,6 +1216,7 @@ stream_ssl_set_ca_cert_file__(const char *file_name, /* Set up CAs for OpenSSL to trust in verifying the peer's * certificate. */ + SSL_CTX_set_cert_store(ctx, X509_STORE_new()); if (SSL_CTX_load_verify_locations(ctx, file_name, NULL) != 1) { VLOG_ERR("SSL_CTX_load_verify_locations: %s", ERR_error_string(ERR_get_error(), NULL)); |
