[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: patch SSL certificate warning

From: Steven Fisher <sflists_at_pyile.com>
Date: 2007-09-04 23:54:30 CEST

On 04-Sep-2007, at 12:45 PM, Matt Bodley wrote:

> I'm not well versed on the details of the TSVN code, when you mean
> library, are you referring to higher level libraries or core
> libraries such as the OpenSSL.

Please don't make this change.

Sure, it would be convenient, but since the whole point of a
certificate warning is to warn that certificates don't match, I don't
want silent acceptance of a certificate that *by definition* does not
match.

RFC 2818 says:
Names may contain the wildcard character * which is considered to
match any single domain name component or component fragment. E.g.,
*.a.com matches foo.a.com but not bar.foo.a.com. f*.com matches
foo.com but not bar.com.

See also:
<http://www.ietf.org/rfc/rfc2818.txt>
<http://www.ietf.org/rfc/rfc2595.txt>
<https://bugzilla.mozilla.org/show_bug.cgi?id=159483>

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tortoisesvn.tigris.org
For additional commands, e-mail: dev-help@tortoisesvn.tigris.org
Received on Wed Sep 5 07:09:43 2007

This is an archived mail posted to the TortoiseSVN Dev mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.