#include <openssl/md5.h>
#include <openssl/conf.h>
#include <openssl/bn.h>
+#ifndef HAVE_BORINGSSL
#include <openssl/ocsp.h>
+#endif
#else
#include <rand.h>
#include <x509v3.h>
return result;
}
+#ifndef HAVE_BORINGSSL
static CURLcode verifystatus(struct connectdata *conn,
struct ssl_connect_data *connssl)
{
return result;
}
+#endif /* HAVE_BORINGSSL */
#endif /* USE_SSLEAY */
return CURLE_OUT_OF_MEMORY;
}
+#ifndef HAVE_BORINGSSL
if(data->set.ssl.verifystatus)
SSL_set_tlsext_status_type(connssl->handle, TLSEXT_STATUSTYPE_ocsp);
+#endif
SSL_set_connect_state(connssl->handle);
infof(data, "\t SSL certificate verify ok.\n");
}
+#ifndef HAVE_BORINGSSL
if(data->set.ssl.verifystatus) {
result = verifystatus(conn, connssl);
if(result) {
return result;
}
}
+#endif
if(!strict)
/* when not strict, we don't bother about the verify cert problems */