Do not enable ClientHello parser for async SNI/OCSP. Use new OpenSSL-1.0.2's API `SSL_set_cert_cb` to pause the handshake process and load the cert/OCSP response asynchronously. Hopefuly this will make whole async SNI/OCSP process much faster and will eventually let us remove the ClientHello parser itself (which is currently used only for async session, see #1462 for the discussion of removing it). NOTE: Ported our code to `SSL_CTX_add1_chain_cert` to use `SSL_CTX_get0_chain_certs` in `CertCbDone`. Test provided for this feature. Fix: https://github.com/iojs/io.js/issues/1423 PR-URL: https://github.com/iojs/io.js/pull/1464 Reviewed-By: Shigeki Ohtsu <ohtsu@iij.ad.jp>
18 lines
533 B
INI
18 lines
533 B
INI
[ req ]
|
|
string_mask = utf8only
|
|
utf8 = yes
|
|
default_bits = 1024
|
|
days = 999
|
|
distinguished_name = req_distinguished_name
|
|
attributes = req_attributes
|
|
prompt = no
|
|
|
|
[ req_distinguished_name ]
|
|
C = HU
|
|
L = Budapest
|
|
O = Tresorit
|
|
CN = Ádám Lippai
|
|
emailAddress = adam.lippai@tresorit.com
|
|
|
|
[ req_attributes ]
|
|
challengePassword = A challenge password
|