You don’t realize how difficult X509 certificate verification is until you actually try to implement it. Jesus.
That should be easy with most libs because normally name checking is a separate call from certificate verification.
-
-
I want to avoid checking signatures twice, which is the case in many libs if you check names separate from chains
-
In the more modern ones I mentioned, that shouldn't be an issue.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.