MXS-2786: Require certificates when verifying peers
When peer verification is enabled, clients must present a certificate.
This commit is contained in:
@ -414,7 +414,7 @@ bool SSL_LISTENER_init(SSL_LISTENER* ssl)
|
|||||||
/* Set to require peer (client) certificate verification */
|
/* Set to require peer (client) certificate verification */
|
||||||
if (ssl->ssl_verify_peer_certificate)
|
if (ssl->ssl_verify_peer_certificate)
|
||||||
{
|
{
|
||||||
SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER, NULL);
|
SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER | SSL_VERIFY_FAIL_IF_NO_PEER_CERT, NULL);
|
||||||
}
|
}
|
||||||
|
|
||||||
/* Set the verification depth */
|
/* Set the verification depth */
|
||||||
|
|||||||
Reference in New Issue
Block a user