Skip to content

Compat layer: address several X509_V_FLAG values set to 0 - #11470

Open
padelsbach wants to merge 1 commit into
wolfSSL:masterfrom
padelsbach:ossl-compat-issue-03
Open

padelsbach wants to merge 1 commit into
wolfSSL:masterfrom
padelsbach:ossl-compat-issue-03

Conversation

@padelsbach

Copy link
Copy Markdown
Contributor

Description

Several X509_V_FLAG defines were found to be zero, and thus X509_VERIFY_PARAM_set_flags would silently accept them silently without making the corresponding change. This PR makes the flags match OpenSSL and returns failure when a caller tries to set unsupported modes.

Testing

Added unit tests

Checklist

  • added tests
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

@padelsbach padelsbach self-assigned this Sep 18, 2026
@padelsbach
padelsbach force-pushed the ossl-compat-issue-03 branch 2 times, most recently from 46f6a77 to 9a14f21 Compare September 28, 2026 21:55
@padelsbach padelsbach assigned wolfSSL-Bot and unassigned padelsbach Sep 28, 2026

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11470

Scan targets checked: wolfssl-src, wolfssl-bugs
Coverage: 1 of 4 in-scope changed file(s) opened by the reviewer; not opened: wolfssl/openssl/ssl.h, wolfssl/openssl/x509.h, wolfssl/ssl.h

Findings: 1
1 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Reported findings require changes before merge.

Review tier: Lite

Comment thread wolfssl/openssl/x509.h
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants