GNU bug report logs - #21227
24.5; tls connections not verified by default

Previous Next

Package: emacs;

Reported by: Glyph <glyph <at> twistedmatrix.com>

Date: Mon, 10 Aug 2015 02:32:01 UTC

Severity: important

Tags: fixed, security

Found in version 24.5

Fixed in version 25.1

Done: Lars Ingebrigtsen <larsi <at> gnus.org>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: Lars Ingebrigtsen <larsi <at> gnus.org>
To: Glyph <glyph <at> twistedmatrix.com>
Cc: 21227 <at> debbugs.gnu.org
Subject: bug#21227: 24.5; tls connections not verified by default
Date: Tue, 29 Dec 2015 14:46:57 +0100
Glyph <glyph <at> twistedmatrix.com> writes:

> In order to have HTTPS connections verified, one must customize the
> behavior of tls.el in a highly non-obvious way:
>
> '(tls-checktrust t)
> '(tls-program
>    (quote
>     ("gnutls-cli --x509cafile $A_CERT_BUNDLE -p %p %h")))
>
> leaving the user to determine an appropriate location for
> $A_CERT_BUNDLE.

This has been fixed in Emacs 25.1. 

-- 
(domestic pets only, the antidote for overdose, milk.)
   bloggy blog: http://lars.ingebrigtsen.no




This bug report was last modified 9 years and 148 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.