owncloud / android

:phone: The ownCloud Android App
GNU General Public License v2.0
3.79k stars 3.05k forks source link

Owncloud Android client does not verify TLSA-record (DANE) #2223

Open wioxjk opened 6 years ago

wioxjk commented 6 years ago

Expected behaviour

Owncloud Client should verify TLSA record

Actual behaviour

Owncloud Client does not verify TLSA record

Steps to reproduce

  1. Set up a invalid TLSA record

######################

It seems that the Owncloud-client does not verify DANE (TLSA-record).

michaelstingl commented 6 years ago

Related: https://github.com/owncloud/client/issues/6521