From: Han Han Date: Thu, 16 Aug 2018 19:41:31 +0000 (-0700) Subject: openssl: return CURLE_PEER_FAILED_VERIFICATION on failure to parse issuer X-Git-Tag: curl-7_62_0~227 X-Git-Url: https://granicus.if.org/sourcecode?a=commitdiff_plain;h=59dc83379a239d20ed04e66b650b232ed1f780aa;p=curl openssl: return CURLE_PEER_FAILED_VERIFICATION on failure to parse issuer Failure to extract the issuer name from the server certificate should return a more specific error code like on other TLS backends. --- diff --git a/lib/vtls/openssl.c b/lib/vtls/openssl.c index a487f553c..ce890fe3c 100644 --- a/lib/vtls/openssl.c +++ b/lib/vtls/openssl.c @@ -3210,7 +3210,7 @@ static CURLcode servercert(struct connectdata *conn, ossl_strerror(ERR_get_error(), error_buffer, sizeof(error_buffer)) ); BIO_free(mem); - return 0; + return CURLE_OUT_OF_MEMORY; } BACKEND->server_cert = SSL_get_peer_certificate(BACKEND->handle); @@ -3257,7 +3257,7 @@ static CURLcode servercert(struct connectdata *conn, if(rc) { if(strict) failf(data, "SSL: couldn't get X509-issuer name!"); - result = CURLE_SSL_CONNECT_ERROR; + result = CURLE_PEER_FAILED_VERIFICATION; } else { infof(data, " issuer: %s\n", buffer);