diff options
author | Lutz Jänicke <jaenicke@openssl.org> | 2000-11-29 16:04:38 +0000 |
---|---|---|
committer | Lutz Jänicke <jaenicke@openssl.org> | 2000-11-29 16:04:38 +0000 |
commit | 0dd2254d7667979ea998af1f480a7841ea864ad5 (patch) | |
tree | b07297012e16ee82c54a74d01029abff3c0f390a /ssl/s2_clnt.c | |
parent | 03a0848922d3a4b1a6f216df1c2470a6b946cd87 (diff) | |
download | openssl-0dd2254d7667979ea998af1f480a7841ea864ad5.tar.gz |
Store verify_result with sessions to avoid potential security hole.
For the server side this was already done one year ago :-(
Diffstat (limited to 'ssl/s2_clnt.c')
-rw-r--r-- | ssl/s2_clnt.c | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/ssl/s2_clnt.c b/ssl/s2_clnt.c index 47dd09c286..28d6d65296 100644 --- a/ssl/s2_clnt.c +++ b/ssl/s2_clnt.c @@ -921,6 +921,7 @@ int ssl2_set_certificate(SSL *s, int type, int len, unsigned char *data) goto err; } ERR_clear_error(); /* but we keep s->verify_result */ + s->session->verify_result = s->verify_result; /* server's cert for this session */ sc=ssl_sess_cert_new(); |