[PATCH] winhttp: Treat a partial certificate chain as having an unknown/invalid CA.
Brendan Shanks
bshanks at codeweavers.com
Tue Jun 16 15:48:22 CDT 2020
Wine-Bug: https://bugs.winehq.org/show_bug.cgi?id=46726
Signed-off-by: Brendan Shanks <bshanks at codeweavers.com>
---
This is needed to connect to https://prod.egonet.codemasters.com,
there's a test app and more info in the bug.
dlls/winhttp/net.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/dlls/winhttp/net.c b/dlls/winhttp/net.c
index 2905d5c535a..0cc2bb2bef7 100644
--- a/dlls/winhttp/net.c
+++ b/dlls/winhttp/net.c
@@ -84,8 +84,10 @@ static DWORD netconn_verify_cert( PCCERT_CONTEXT cert, WCHAR *server, DWORD secu
if (!(security_flags & SECURITY_FLAG_IGNORE_CERT_DATE_INVALID))
err = ERROR_WINHTTP_SECURE_CERT_DATE_INVALID;
}
- else if (chain->TrustStatus.dwErrorStatus &
- CERT_TRUST_IS_UNTRUSTED_ROOT)
+ else if ((chain->TrustStatus.dwErrorStatus &
+ CERT_TRUST_IS_UNTRUSTED_ROOT) ||
+ (chain->TrustStatus.dwErrorStatus &
+ CERT_TRUST_IS_PARTIAL_CHAIN))
{
if (!(security_flags & SECURITY_FLAG_IGNORE_UNKNOWN_CA))
err = ERROR_WINHTTP_SECURE_INVALID_CA;
--
2.26.2
More information about the wine-devel
mailing list