Fix docs for X509_CRL_get0_by_serial() and X509_CRL_get0_by_cert()
authorRichard Levitte <levitte@openssl.org>
Mon, 20 Mar 2017 11:29:37 +0000 (12:29 +0100)
committerRichard Levitte <levitte@openssl.org>
Mon, 20 Mar 2017 13:35:31 +0000 (14:35 +0100)
They both return 2 when the revoked entry that's found has the reason
removeFromCRL.

Reviewed-by: Rich Salz <rsalz@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/2993)

doc/man3/X509_CRL_get0_by_serial.pod

index d9d4360fe01688b14b9402b6d7bca28bb63a127d..a704228eb9ec0dc99d0cab3a7b506ea15f260b09 100644 (file)
@@ -70,7 +70,10 @@ in turn using sk_X509_REVOKED_value().
 
 =head1 RETURN VALUES
 
-X509_CRL_get0_by_serial(), X509_CRL_get0_by_cert(),
+X509_CRL_get0_by_serial() and X509_CRL_get0_by_cert() return 0 for failure,
+1 on success except if the revoked entry has the reason C<removeFromCRL> (8),
+in which case 2 is returned.
+
 X509_REVOKED_set_serialNumber(), X509_REVOKED_set_revocationDate(),
 X509_CRL_add0_revoked() and X509_CRL_sort() return 1 for success and 0 for
 failure.