Store verify_result with sessions to avoid potential security hole.
[openssl.git] / ssl / s2_srvr.c
index 9aeedef55f62dc5188c47005beda1870ce0612d1..f8f1ba76d0d77220715f2adb4591b4e4f99667a8 100644 (file)
@@ -921,6 +921,7 @@ static int request_certificate(SSL *s)
                                X509_free(s->session->peer);
                        s->session->peer=x509;
                        CRYPTO_add(&x509->references,1,CRYPTO_LOCK_X509);
+                       s->session->verify_result = s->verify_result;
                        ret=1;
                        goto end;
                        }