X509 verification fixes.
authorDr. Stephen Henson <steve@openssl.org>
Sun, 13 Jul 2008 14:25:36 +0000 (14:25 +0000)
committerDr. Stephen Henson <steve@openssl.org>
Sun, 13 Jul 2008 14:25:36 +0000 (14:25 +0000)
commitdb50661fce82a8f32bccaa7454be4041cbfad6d0
tree761d5622052f34f9e45f906bff544792af5efc75
parentf9afd9f861bc7b5fc1ae32ceff15572ef73cbbec
X509 verification fixes.

Ignore self issued certificates when checking path length constraints.

Duplicate OIDs in policy tree in case they are allocated.

Use anyPolicy from certificate cache and not current tree level.
apps/cms.c
crypto/x509/x509_vfy.c
crypto/x509v3/pcy_data.c
crypto/x509v3/pcy_tree.c
crypto/x509v3/v3_purp.c
crypto/x509v3/x509v3.h
doc/apps/verify.pod