revocation: Enforce a (configurable) timeout when fetching OCSP/CRL
Malicious servers could otherwise block the fetching thread indefinitely after the initial TCP handshake (which has a default timeout of 10s in the curl and winhttp plugins, the soup plugin actually has a default overall timeout of 10s).
This commit is contained in:
@@ -4,4 +4,5 @@ charon.plugins.revocation.enable_ocsp = yes
|
||||
charon.plugins.revocation.enable_crl = yes
|
||||
Whether CRL validation should be enabled.
|
||||
|
||||
|
||||
charon.plugins.revocation.timeout = 10s
|
||||
Timeout used when fetching OCSP/CRL.
|
||||
|
||||
Reference in New Issue
Block a user