From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: Christopher Schmidt Newsgroups: gmane.emacs.devel Subject: Re: using GnuTLS 3.x and certificate checks Date: Wed, 10 Apr 2013 21:35:18 +0100 (BST) Message-ID: <874nfenmya@ch.ristopher.com> References: <87zjxumbjf.fsf@wanadoo.es> <87sj3jcr6t.fsf@wanadoo.es> <86zjxrs4jm.fsf@gmail.com> <87k3ovcn1r.fsf@wanadoo.es> <86fvzj2gkz.fsf@gmail.com> <87sj3jaqfs.fsf@wanadoo.es> <83y5dazmpt.fsf@gnu.org> <86ehf2zefk.fsf@gmail.com> <86li9az2sw.fsf@gmail.com> <83hajyz1mi.fsf@gnu.org> <867gku88lx.fsf@gmail.com> <83a9pqysc5.fsf@gnu.org> <86sj3i6ndd.fsf@gmail.com> <83620eyonh.fsf@gnu.org> <86620dqmsd.fsf@gmail.com> <83r4j1xmim.fsf@gnu.org> <86y5d9p4oh.fsf@gmail.com> <83ppylxidt.fsf@gnu.org> <86txnxoz1k.fsf@gmail.com> <83hajxxd5c.fsf@gnu.org> <874nfxt219.fsf_-_@lifelogs.com> NNTP-Posting-Host: plane.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: ger.gmane.org 1365626127 8932 80.91.229.3 (10 Apr 2013 20:35:27 GMT) X-Complaints-To: usenet@ger.gmane.org NNTP-Posting-Date: Wed, 10 Apr 2013 20:35:27 +0000 (UTC) To: emacs-devel@gnu.org Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Wed Apr 10 22:35:31 2013 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by plane.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1UQ1ju-0005J9-6F for ged-emacs-devel@m.gmane.org; Wed, 10 Apr 2013 22:35:30 +0200 Original-Received: from localhost ([::1]:47850 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1UQ1jt-0001EG-Pl for ged-emacs-devel@m.gmane.org; Wed, 10 Apr 2013 16:35:29 -0400 Original-Received: from eggs.gnu.org ([208.118.235.92]:34103) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1UQ1jn-00017g-EU for emacs-devel@gnu.org; Wed, 10 Apr 2013 16:35:26 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1UQ1jl-0002jZ-5S for emacs-devel@gnu.org; Wed, 10 Apr 2013 16:35:23 -0400 Original-Received: from ristopher.com ([146.185.21.93]:39163 helo=saturn.ch.ristopher.com) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1UQ1jk-0002jA-UD for emacs-devel@gnu.org; Wed, 10 Apr 2013 16:35:21 -0400 Original-Received: by saturn.ch.ristopher.com (Postfix, from userid 0) id DCF3620E13; Wed, 10 Apr 2013 21:35:18 +0100 (BST) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=ch.ristopher.com; s=mail; t=1365626118; bh=OHaM2uUteoHBB7zkhNbw8DWZjeB9LMrP/IA0wMtiHUk=; h=From:To:Subject:In-Reply-To:Message-ID:References:MIME-Version: Content-Type:Date; b=bVnVZEb4q4TpOr7yquslPPvJNv1eT9Nd/CfUFvU7WRLVkj8HCQA8km0uufFfzJjA/ rzvIhKE3djI1YDGmxaYsjvUqq4UeKuK0RLr7kX+gtiAh3X98lGyXnwGJzygmRuD6U4 gRQiSLiC1os0AtR8+NwnWOOv+tVHSlxqxouukTyk= In-Reply-To: <874nfxt219.fsf_-_@lifelogs.com> (Ted Zlatanov's message of "Wed, 27 Mar 2013 09:17:38 -0400") Mail-Followup-To: emacs-devel@gnu.org X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.4.x X-Received-From: 146.185.21.93 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.devel:158830 Archived-At: Ted Zlatanov writes: > This would also be a good time to enable SSL certificate verification > by default. That's a great idea. What do you think about a user-customizable verification mechanism? This could be as simple as passing host, port and the PEM-encoded cert chain to a regular function that will return non-nil if the verification failed. Christopher