| Age | Commit message (Collapse) | Author | 
 | 
The certificate generation scripts were also updated to better match the
format of the certificates currently checked in.
 | 
 | 
 | 
 | 
Option --pinnedpubkey takes a path to a public key in DER format and
only connect if it matches (currently only implemented with OpenSSL).
Provides CURLOPT_PINNEDPUBLICKEY for curl_easy_setopt().
Extract a public RSA key from a website like so:
openssl s_client -connect google.com:443 2>&1 < /dev/null | \
sed -n '/-----BEGIN/,/-----END/p' | openssl x509 -noout -pubkey \
| openssl rsa -pubin -outform DER > google.com.der
 | 
 | 
 | 
 | 
 | 
 | 
... and make it possible to do so without any user interaction
 | 
 | 
 | 
 | 
each test, so that the test suite can now be used to actually test the
  verification of cert names etc. This made an error show up in the OpenSSL-
  specific code where it would attempt to match the CN field even if a
  subjectAltName exists that doesn't match. This is now fixed and verified
  in test 311.
 |