credential-manager: Log subject of trusted cert before building trust chain
This should make it clearer to what the log messages generated by verify_trust_chain() are related (in particular if building the chain fails or the cert has expired).
This commit is contained in:
@@ -867,6 +867,8 @@ METHOD(enumerator_t, trusted_enumerate, bool,
|
|||||||
this->pretrusted = get_pretrusted_cert(this->this, this->type, this->id);
|
this->pretrusted = get_pretrusted_cert(this->this, this->type, this->id);
|
||||||
if (this->pretrusted)
|
if (this->pretrusted)
|
||||||
{
|
{
|
||||||
|
DBG1(DBG_CFG, " using trusted certificate \"%Y\"",
|
||||||
|
this->pretrusted->get_subject(this->pretrusted));
|
||||||
/* if we find a trusted self signed certificate, we just accept it.
|
/* if we find a trusted self signed certificate, we just accept it.
|
||||||
* However, in order to fulfill authorization rules, we try to build
|
* However, in order to fulfill authorization rules, we try to build
|
||||||
* the trust chain if it is not self signed */
|
* the trust chain if it is not self signed */
|
||||||
@@ -874,8 +876,6 @@ METHOD(enumerator_t, trusted_enumerate, bool,
|
|||||||
verify_trust_chain(this->this, this->pretrusted, this->auth,
|
verify_trust_chain(this->this, this->pretrusted, this->auth,
|
||||||
TRUE, this->online))
|
TRUE, this->online))
|
||||||
{
|
{
|
||||||
DBG1(DBG_CFG, " using trusted certificate \"%Y\"",
|
|
||||||
this->pretrusted->get_subject(this->pretrusted));
|
|
||||||
*cert = this->pretrusted;
|
*cert = this->pretrusted;
|
||||||
if (!this->auth->get(this->auth, AUTH_RULE_SUBJECT_CERT))
|
if (!this->auth->get(this->auth, AUTH_RULE_SUBJECT_CERT))
|
||||||
{ /* add cert to auth info, if not returned by trustchain */
|
{ /* add cert to auth info, if not returned by trustchain */
|
||||||
|
|||||||
Reference in New Issue
Block a user