diff options
| author | Mårten Nordheim <marten.nordheim@qt.io> | 2023-05-10 16:43:41 +0200 |
|---|---|---|
| committer | Mårten Nordheim <marten.nordheim@qt.io> | 2023-05-23 14:29:59 +0200 |
| commit | ada2c573c1a25f8d96577734968fe317ddfa292a (patch) | |
| tree | 79bab1fad9c38dacb2ec7c350b557f7ca1f7d695 /examples/opengl/qopenglwidget/glwidget.cpp | |
| parent | 2385d669231c8c3af3aab1ae31fa0e4c9f170f1e (diff) | |
Schannel: Reject certificate not signed by a configured CA certificate
Not entirely clear why, but when building the certificate chain for a
peer the system certificate store is searched for root certificates.
General expectation is that after calling
`sslConfiguration.setCaCertificates()` the system certificates will
not be taken into consideration.
To work around this behavior, we do a manual check that the root of the
chain is part of the configured CA certificates.
Pick-to: 6.5 6.2 5.15
Change-Id: I03666a4d9b0eac39ae97e150b4743120611a11b3
Reviewed-by: Edward Welbourne <edward.welbourne@qt.io>
Reviewed-by: Volker Hilsheimer <volker.hilsheimer@qt.io>
Diffstat (limited to 'examples/opengl/qopenglwidget/glwidget.cpp')
0 files changed, 0 insertions, 0 deletions
