diff options
author | Pierre Ossman <ossman@cendio.se> | 2020-05-21 21:10:38 +0200 |
---|---|---|
committer | Pierre Ossman <ossman@cendio.se> | 2020-09-08 14:14:41 +0200 |
commit | 7399eab79a4365434d26494fa1628ce1eb91562b (patch) | |
tree | 090184650960f1b253fbf4fbf7fa0bff8af9da97 /common/rdr/MemInStream.h | |
parent | f81c4b683036337e7063f506c96a953f0504f3d3 (diff) | |
download | tigervnc-7399eab79a4365434d26494fa1628ce1eb91562b.tar.gz tigervnc-7399eab79a4365434d26494fa1628ce1eb91562b.zip |
Properly store certificate exceptions
The previous method stored the certificates as authorities, meaning that
the owner of that certificate could impersonate any server it wanted
after a client had added an exception.
Handle this more properly by only storing exceptions for specific
hostname/certificate combinations, the same way browsers or SSH does
things.
(cherry picked from commit b30f10c681ec87720cff85d490f67098568a9cba)
Diffstat (limited to 'common/rdr/MemInStream.h')
0 files changed, 0 insertions, 0 deletions