Bug#792490: openssl s_client doesn't allow for certificate pinning anymore!

2015-09-07 Thread Ben Hutchings
Control: severity -1 important Control: tag -1 - security On Wed, 15 Jul 2015 12:52:24 +0200 Florent Daigniere < nextg...@freenetproject.org> wrote: > Package: openssl > Version: 1.0.2d-1 > Severity: grave > Tags: security > Justification: user security hole > > Dear Maintainer, > > It looks lik

Bug#792490: openssl s_client doesn't allow for certificate pinning anymore!

2015-07-15 Thread Florent Daigniere
Package: openssl Version: 1.0.2d-1 Severity: grave Tags: security Justification: user security hole Dear Maintainer, It looks like openssl s_client is not providing any way to disregard the system's trusted CAs anymore... and this is a regression from Jessie. with 1.0.2d-1 (sid) $strace -f -e o