Re: (ITS#5361) cert verification failures with GnuTLS and DNS subjectAlt

From: Nikos Mavrogiannopoulos
Subject: Re: (ITS#5361) cert verification failures with GnuTLS and DNS subjectAltName
Date: Fri, 15 Feb 2008 22:16:24 +0200
On Friday 15 February 2008, Howard Chu wrote:
> Nikos Mavrogiannopoulos wrote:
> > Indeed I'll try to improve this patch to work only for formats known
> > to be text.
> The code was perfectly correct before this patch. Why do you want to change
> anything here at all? I looked in the gnutls-devel archives and couldn't
> find any discussion of this change. It would be nice to understand what
> you're trying to accomplish here, given that there are large bodies of code
> already written that expect the existing behavior of GnuTLS 2.1.7 and
> older.

Well, it depends on the definition of correct. It didn't null terminate 
printable strings, and this was so correct for me. Anyway, does the attached 
patch solve your problem?


