Skip to content

Pingora's patch disabling cert version validation for extensions#495

Open
kornelski wants to merge 4 commits intomasterfrom
bad-certs
Open

Pingora's patch disabling cert version validation for extensions#495
kornelski wants to merge 4 commits intomasterfrom
bad-certs

Conversation

@kornelski
Copy link
Copy Markdown
Collaborator

Needed by Pingora to unfork boring.

@kornelski kornelski requested a review from cjpatton April 21, 2026 17:08
Copy link
Copy Markdown
Collaborator

@cjpatton cjpatton left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is unfortunate but seems relatively harmless. Sometimes you just have to match OpenSSL.

Note that OpenSSL can be configured to be as strict as BoringSSL here, but is not configured this way by default. See X509_V_FLAG_X509_STRICT in https://docs.openssl.org/master/man3/X509_VERIFY_PARAM_set_flags/#description

Comment thread boring-sys/Cargo.toml Outdated
Co-authored-by: Christopher Patton <cpatton@cloudflare.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants