mirror of
https://github.com/yhirose/cpp-httplib.git
synced 2026-10-08 04:13:47 +00:00
verify_cert_with_windows_schannel() rejected a chain whenever TrustStatus.dwErrorStatus was non-zero, before CertVerifyCertificateChainPolicy() ran. The CERT_CHAIN_POLICY_IGNORE_ALL_REV_UNKNOWN_FLAGS flag passed to that policy check was therefore dead code: a certificate without revocation information, or one whose CRL could not be fetched, failed with CERT_TRUST_REVOCATION_STATUS_UNKNOWN. Drop the pre-check so the SSL chain policy is the only judge. Revocation checking becomes best-effort: a revoked certificate and every other chain error are still rejected, while an undetermined revocation status is accepted. On a rejected chain, ssl_backend_error() now holds the policy status, such as CERT_E_UNTRUSTEDROOT, instead of the trust status bit mask.