SCT: add validation of proofs for extensions and OCSP.

This does not yet work for certificates, because this requires some
changing the ASN.1 structure before validation (we need to extract the
tbscert and remove the SCT extension before).

API will change in the future.
This commit is contained in:
Johanna Amann 2017-03-17 11:40:49 -07:00
parent d50bddfbfb
commit c403a7f4e6
6 changed files with 171 additions and 0 deletions

View file

@ -1,6 +1,7 @@
%%{
#include "analyzer/protocol/ssl/SSL.h"
#include <openssl/x509.h>
%%}
## Sets if the SSL analyzer should consider the connection established (handshake