Skip to content

Conversation

@bagder
Copy link
Member

@bagder bagder commented Sep 20, 2025

Since it would indicate errors to the degree that continuing would just risk hiding the earlier errors or make things weird.

Inspired by a report in Joshua's sarif data

@bagder bagder added the TLS label Sep 20, 2025
@bagder bagder marked this pull request as ready for review September 20, 2025 20:34
@testclutch

This comment was marked as resolved.

@bagder
Copy link
Member Author

bagder commented Sep 21, 2025

@icing when you have a sec, please tell me why this PR is wrong! (fails tests) 😁

@icing
Copy link
Contributor

icing commented Sep 25, 2025

When a TLS session is resumed, the server does not send the certificate chain. And OpenSSL also does not have it. octx->reused_session is the flag for this.

@bagder
Copy link
Member Author

bagder commented Sep 25, 2025

Ah, excellent. Thanks!

Since it would indicate errors to the degree that continuing would just
risk hiding the earlier errors or make things weird.

Inspired by a report in Joshua's sarif data
@bagder bagder force-pushed the bagder/openssl-certchain branch from a162eb4 to ab525a5 Compare September 25, 2025 17:48
@bagder bagder closed this in 16e0a20 Sep 25, 2025
@bagder bagder deleted the bagder/openssl-certchain branch September 25, 2025 20:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Development

Successfully merging this pull request may close these issues.

3 participants