Elektrine lite

← Feed

@23n27@dgc.social

Post #4291395

2026-07-21 13:19 UTC

From the "how could this ever work" department, TIL: OpenSSL also uses the supplied CA pool for completing client chains if necessary (and many tools don't really allow you to distinguish between the two, so you end up having to put in client intermediates into the pool that is used to verify server certs. Not much of a problem if your PKI is sane, but still unelegant)

Replies (0)

No replies.