Closed GoogleCodeExporter closed 9 years ago
Digged into the spec and found:
http://tools.ietf.org/html/rfc3920#page-19
Certificates MUST be checked against the hostname as provided by
the initiating entity (e.g., a user), not the hostname as
resolved via the Domain Name System; e.g., if the user specifies
a hostname of "example.com" but a DNS SRV [SRV] lookup returned
So looks like a bug in the library.
Original comment by kot.bege...@gmail.com
on 16 Dec 2007 at 1:15
Fixed, along with a Mentalis StartTLS race condition.
Original comment by hil...@gmail.com
on 19 Dec 2007 at 9:51
Original issue reported on code.google.com by
kot.bege...@gmail.com
on 15 Dec 2007 at 11:59