Re: [PATCH 6/7] virNetTLSCertSanityCheck: Validate all concatenated certs

2025-07-18 Thread Daniel P . Berrangé via Devel
On Fri, Jul 18, 2025 at 12:32:39PM +0200, Peter Krempa wrote: > On Fri, Jul 18, 2025 at 09:24:05 +0100, Daniel P. Berrangé wrote: > > On Fri, Jul 18, 2025 at 09:39:22AM +0200, Peter Krempa wrote: > > > On Thu, Jul 17, 2025 at 17:02:33 +0100, Daniel P. Berrangé wrote: > > > > On Thu, Jul 17, 2025 at

Re: [PATCH 6/7] virNetTLSCertSanityCheck: Validate all concatenated certs

2025-07-18 Thread Peter Krempa via Devel
On Fri, Jul 18, 2025 at 09:24:05 +0100, Daniel P. Berrangé wrote: > On Fri, Jul 18, 2025 at 09:39:22AM +0200, Peter Krempa wrote: > > On Thu, Jul 17, 2025 at 17:02:33 +0100, Daniel P. Berrangé wrote: > > > On Thu, Jul 17, 2025 at 05:28:09PM +0200, Peter Krempa via Devel wrote: > > > > From: Peter K

Re: [PATCH 6/7] virNetTLSCertSanityCheck: Validate all concatenated certs

2025-07-18 Thread Daniel P . Berrangé via Devel
On Fri, Jul 18, 2025 at 09:39:22AM +0200, Peter Krempa wrote: > On Thu, Jul 17, 2025 at 17:02:33 +0100, Daniel P. Berrangé wrote: > > On Thu, Jul 17, 2025 at 05:28:09PM +0200, Peter Krempa via Devel wrote: > > > From: Peter Krempa > > > > > > Similarly to how we iterate the list of CAs in the con

Re: [PATCH 6/7] virNetTLSCertSanityCheck: Validate all concatenated certs

2025-07-18 Thread Peter Krempa via Devel
On Thu, Jul 17, 2025 at 17:02:33 +0100, Daniel P. Berrangé wrote: > On Thu, Jul 17, 2025 at 05:28:09PM +0200, Peter Krempa via Devel wrote: > > From: Peter Krempa > > > > Similarly to how we iterate the list of CAs in the concatenated bundle > > there's a possibility of the server/client certific

Re: [PATCH 6/7] virNetTLSCertSanityCheck: Validate all concatenated certs

2025-07-17 Thread Daniel P . Berrangé via Devel
On Thu, Jul 17, 2025 at 05:28:09PM +0200, Peter Krempa via Devel wrote: > From: Peter Krempa > > Similarly to how we iterate the list of CAs in the concatenated bundle > there's a possibility of the server/client certificates to be > concatenated as well. > > If for some case the first certifica