add profanity-specific CAfile

The profanity-internal mechanism to allow connecting to a server isn't
easily portable to cURL. Therefor introduce a profanity-specific CAfile
which is managed individually and will be configured in libcurl calls.

Signed-off-by: Steffen Jaeckel <jaeckel-floss@eyet-services.de>
This commit is contained in:
Steffen Jaeckel
2022-03-22 11:26:53 +01:00
parent b28ac09368
commit 7f1f9787cb
9 changed files with 226 additions and 0 deletions

View File

@@ -47,6 +47,7 @@
#include "config/preferences.h"
#include "config/tlscerts.h"
#include "config/account.h"
#include "config/cafile.h"
#include "config/scripts.h"
#include "event/client_events.h"
#include "event/common.h"
@@ -1138,6 +1139,7 @@ sv_ev_certfail(const char* const errormsg, const TLSCertificate* cert)
{
// check profanity trusted certs
if (tlscerts_exists(cert->fingerprint)) {
cafile_add(cert);
return 1;
}
@@ -1181,6 +1183,7 @@ sv_ev_certfail(const char* const errormsg, const TLSCertificate* cert)
cons_show("Adding %s to trusted certificates.", cert->fingerprint);
if (!tlscerts_exists(cert->fingerprint)) {
tlscerts_add(cert);
cafile_add(cert);
}
free(cmd);
return 1;