vtls: move 'native_ca_store' ssl_config_data => ssl_primary_config
Some checks failed
configure-vs-cmake / Linux (push) Failing after 5s
dist / AM in-tree & maketgz (push) Failing after 4s
dist / reproducible releases (push) Failing after 2s
dist / AM out-of-tree docs (push) Has been skipped
dist / AM out-of-tree !perl (push) Has been skipped
dist / CM in-tree !perl (push) Has been skipped
dist / AM out-of-tree (debug) (push) Has been skipped
dist / AM in-tree !perl (push) Has been skipped
dist / CM out-of-tree !perl (push) Has been skipped
dist / missing files (push) Has been skipped
Linux / CM libressl Fil-C (push) Failing after 1m45s
Linux / AM mbedtls clang (push) Failing after 1m45s
Linux Old / autotools & cmake (push) Failing after 1m48s
Linux / AM openssl clang krb5 openldap static (push) Failing after 3s
Linux / AM openssl i686 (push) Failing after 3s
Linux / AM IntelC openssl (push) Failing after 3s
Linux / CM openssl -O3 libssh valgrind 1 (push) Failing after 3s
Linux / CM openssl -O3 libssh valgrind 2 (push) Failing after 3s
Linux / AM awslc (push) Failing after 3s
Linux / CM mbedtls-prev (push) Failing after 2s
Linux / AM event-based (push) Failing after 3s
Linux / AM Alpine MUSL https-rr c-ares (push) Failing after 3s
Linux / AM Alpine MUSL https-rr (push) Failing after 5s
Linux / AM openssl default (push) Failing after 3s
Linux / AM rustls (push) Failing after 5s
Linux / AM openssl intel C89 (push) Failing after 4s
Linux / CM mbedtls-pkg MultiSSL !pc (push) Failing after 5s
Linux / CM openssl torture 1 (push) Failing after 4s
Linux / CM openssl torture 2 (push) Failing after 4s
Linux / CM rustls valgrind 1 (push) Failing after 4s
Linux / CM rustls valgrind 2 (push) Failing after 3s
Linux / CM awslc (push) Failing after 3s
Linux / CM boringssl (push) Failing after 4s
non-native / freebsd 14.3, AM clang openssl !examples arm64 (push) Failing after 1s
non-native / freebsd 14.3, CM clang openssl arm64 (push) Failing after 2s
non-native / freebsd 15.1, CM clang openssl !examples riscv64 (push) Failing after 2s
non-native / openbsd 7.9, AM clang libressl !examples x86_64 (push) Failing after 2s
non-native / freebsd 15.1, AM clang openssl x86_64 (push) Failing after 2s
non-native / netbsd 10.1, AM gcc openssl !examples x86_64 (push) Failing after 3s
non-native / midnightbsd 4.0.4, CM clang gnutls x86_64 (push) Failing after 2s
non-native / openbsd 7.9, CM clang libressl x86_64 (push) Failing after 2s
non-native / netbsd 11.0, CM gcc openssl x86_64 (push) Failing after 3s
non-native / freebsd 15.1, CM clang openssl !unity !examples x86_64 (push) Failing after 5s
non-native / AmigaOS, AM gcc AmiSSL m68k (push) Failing after 3s
non-native / AmigaOS, CM gcc AmiSSL m68k (push) Failing after 4s
non-native / Android 21, AM !ssl !zstd arm64 (push) Failing after 3s
non-native / Android 35, AM !ssl !zstd arm64 (push) Failing after 3s
non-native / Android 21, CM !ssl !zstd arm64 (push) Failing after 2s
non-native / Android 35, CM !ssl !zstd arm64 (push) Failing after 2s
non-native / MS-DOS, AM djgpp !ssl i586 (push) Failing after 3s
non-native / MS-DOS, CM djgpp !ssl i586 (push) Failing after 4s
Linux / AM Slackware !ssl gssapi gcc (push) Failing after 1m13s
Docs / proselint (push) Has been cancelled
Docs / pyspelling (push) Has been cancelled
Docs / synopsis, man-examples (push) Has been cancelled
Source / checksrc (push) Has been cancelled
Source / spellcheck, linters, REUSE (push) Has been cancelled
Source / pytype (push) Has been cancelled
Source / complexity and function sizes (push) Has been cancelled
Source / xmllint (push) Has been cancelled
Source / misc checks (push) Has been cancelled
Fuzzer / Fuzzing (push) Has been cancelled
Linux HTTP/3 / Build caches (push) Has been cancelled
URLs / linkcheck (push) Has been cancelled
CodeQL / GHA and Python (push) Has been cancelled
CodeQL / C (push) Has been cancelled
CodeQL / C-1 (push) Has been cancelled
configure-vs-cmake / macOS (push) Has been cancelled
configure-vs-cmake / Windows (push) Has been cancelled
curl-for-win / Linux gcc glibc (amd64, arm64) (push) Has been cancelled
curl-for-win / Linux gcc glibc minimal (amd64) (push) Has been cancelled
Linux / CM clang-tidy H3 c-ares !examples (push) Has been cancelled
Linux / CM clang-tidy (push) Has been cancelled
Linux / CM address-sanitizer (push) Has been cancelled
Linux / CM address-sanitizer H3 c-ares (push) Has been cancelled
Linux / AM memory-sanitizer (push) Has been cancelled
Linux / CM thread-sanitizer (push) Has been cancelled
Linux / CM openssl libssh2 sync-resolver valgrind 2 (push) Has been cancelled
Linux / CM openssl libssh2 sync-resolver valgrind 1 +analyzer (push) Has been cancelled
Linux / AM libressl krb5 (push) Has been cancelled
Linux / CM mbedtls gss valgrind 1 (push) Has been cancelled
Linux / CM mbedtls gss valgrind 2 (push) Has been cancelled
Linux / AM wolfssl-all (push) Has been cancelled
Linux / AM wolfssl-opensslextra valgrind 1 (push) Has been cancelled
Linux / AM wolfssl-opensslextra valgrind 2 (push) Has been cancelled
Linux / AM duphandle (push) Has been cancelled
Linux / AM curl_global_init_mem debug valgrind (push) Has been cancelled
Linux / AM openssl !ipv6 !--libcurl !--digest-auth (push) Has been cancelled
macOS / CM clang MultiSSL AppleIDN clang-tidy +examples (push) Has been cancelled
macOS / CM clang HTTP/3 clang-tidy (push) Has been cancelled
macOS / AM clang OpenSSL libssh c-ares (push) Has been cancelled
macOS / AM clang OpenSSL SecTrust krb5 (push) Has been cancelled
macOS / CM clang wolfSSL !ldap brotli zstd (push) Has been cancelled
curl-for-win / Linux llvm MUSL (amd64, riscv64) (push) Has been cancelled
curl-for-win / macOS clang cares (x86_64) (push) Has been cancelled
curl-for-win / Windows llvm (x64) (push) Has been cancelled
curl-for-win / Windows gcc zlib-classic (x64) (push) Has been cancelled
dist / CM integration macos-latest (push) Has been cancelled
dist / CM integration ubuntu-26.04-arm (push) Has been cancelled
dist / CM integration windows-2022 (push) Has been cancelled
dist / Verify tarball downloads (push) Has been cancelled
Linux / AM libressl clang (push) Has been cancelled
Linux / CM openssl clang krb5 LTO (push) Has been cancelled
Linux / AM openssl https-only (push) Has been cancelled
Linux / AM !ssl !http !smtp !imap (push) Has been cancelled
Linux / AM openssl arm C89 (push) Has been cancelled
Linux / CM libressl krb5 valgrind 1 (push) Has been cancelled
Linux / CM libressl krb5 valgrind 2 (push) Has been cancelled
macOS / iOS, AM libressl arm64 (push) Has been cancelled
macOS / iOS, CM-Xcode libressl arm64 (push) Has been cancelled
macOS / CM clang LibreSSL openldap AppleGSS c-ares +examples (push) Has been cancelled
macOS / CM clang OpenSSL event-based (push) Has been cancelled
macOS / CM clang OpenSSL 10.15 C89 (push) Has been cancelled
macOS / CM clang OpenSSL gsasl AppleIDN SecTrust +examples (push) Has been cancelled
macOS / AM gcc-13 !ssl !debug brotli zstd (push) Has been cancelled
macOS / CM gcc-15 aws-lc +analyzer (push) Has been cancelled
macOS / CM llvm@18 mbedTLS !ldap brotli zstd MultiSSL AppleIDN (push) Has been cancelled
macOS / CM llvm@18 OpenSSL libssh (push) Has been cancelled
macOS / AM clang macos-26 (push) Has been cancelled
macOS / CM gcc-13 macos-14 (push) Has been cancelled
macOS / CM gcc-15 macos-14 (push) Has been cancelled
macOS / CM gcc-15 macos-15 (push) Has been cancelled
macOS / CM clang OpenSSL torture 1 (push) Has been cancelled
macOS / CM clang OpenSSL torture 2 (push) Has been cancelled
macOS / CM clang OpenSSL torture 3 (push) Has been cancelled
macOS / CM clang GnuTLS !ldap krb5 +examples (push) Has been cancelled
macOS / CM clang !ssl libssh2 AppleIDN (push) Has been cancelled
macOS / CM clang Rustls (push) Has been cancelled
macOS / CM clang !ssl HTTP-only c-ares (push) Has been cancelled
macOS / CM clang LibreSSL !ldap +examples (push) Has been cancelled
macOS / CM clang macos-14 (push) Has been cancelled
macOS / CM clang macos-26 (push) Has been cancelled
Windows / linux-mingw, AM gcc (push) Has been cancelled
Windows / linux-mingw, CM gcc (push) Has been cancelled
macOS / CM gcc-15 macos-26 (push) Has been cancelled
macOS / CM llvm@15 macos-14 (push) Has been cancelled
macOS / CM llvm@20 macos-26 (push) Has been cancelled
Windows / Build caches (push) Has been cancelled
Windows / Build caches-1 (push) Has been cancelled
Windows / linux-mingw, CM clang-tidy (push) Has been cancelled
Linux HTTP/3 / AM gnutls (push) Has been cancelled
Linux HTTP/3 / AM awslc (push) Has been cancelled
Linux HTTP/3 / AM boringssl (push) Has been cancelled
Linux HTTP/3 / CM gnutls (push) Has been cancelled
Linux HTTP/3 / AM libressl (push) Has been cancelled
Linux HTTP/3 / AM openssl-prev (push) Has been cancelled
Linux HTTP/3 / AM openssl (push) Has been cancelled
Linux HTTP/3 / AM quiche (push) Has been cancelled
Linux HTTP/3 / AM wolfssl (push) Has been cancelled
Linux HTTP/3 / CM awslc (push) Has been cancelled
Linux HTTP/3 / CM boringssl (push) Has been cancelled
Linux HTTP/3 / CM libressl (push) Has been cancelled
Linux HTTP/3 / CM quiche (push) Has been cancelled
Linux HTTP/3 / CM openssl-prev (push) Has been cancelled
Linux HTTP/3 / CM openssl (push) Has been cancelled
Linux HTTP/3 / CM wolfssl (push) Has been cancelled
Windows / cygwin, AM x86_64 openssl R (push) Has been cancelled
Windows / cygwin, CM x86_64 openssl (push) Has been cancelled
Windows / msys2, AM x86_64 !proxy (push) Has been cancelled
Windows / msys2, AM x86_64 default (push) Has been cancelled
Windows / mingw, AM x86_64 default (push) Has been cancelled
Windows / mingw, AM ucrt-x86_64 wolfssl c-ares U (push) Has been cancelled
Windows / msys2, AM x86_64 default R (push) Has been cancelled
Windows / mingw, CM ucrt-x86_64 openssl uwp (push) Has been cancelled
Windows / mingw, CM clang-aarch64 schannel R (push) Has been cancelled
Windows / mingw, CM i686 MultiSSL R (push) Has been cancelled
Windows / mingw, CM clang-x86_64 gnutls libssh (push) Has been cancelled
Windows / mingw, CM x86_64 schannel c-ares U (push) Has been cancelled
Windows / mingw, CM ucrt-x86_64 schannel U torture 1 (push) Has been cancelled
Windows / mingw, CM ucrt-x86_64 schannel U torture 2 (push) Has been cancelled
Windows / mingw, CM x86_64 schannel dev debug (push) Has been cancelled
Windows / msys2, CM x86_64 default (push) Has been cancelled
Windows / mingw, CM clang-x86_64 openssl (push) Has been cancelled
Windows / dl-mingw, CM 6.4.0-i686 schannel !unity (push) Has been cancelled
Windows / dl-mingw, CM 4.8.1-x86_64 schannel !examples (push) Has been cancelled
Windows / dl-mingw, CM 9.5.0-x86_64 schannel (push) Has been cancelled
Windows / dl-mingw, CM 16.1.0-x86_64 schannel +analyzer (push) Has been cancelled
Windows / dl-mingw, CM 7.3.0-x86_64 schannel mbedtls U (push) Has been cancelled
Windows / msvc, CM arm64-windows schannel U (push) Has been cancelled
Windows / msvc, CM x64-uwp !ssl +examples (push) Has been cancelled
Windows / msvc, CM x64-windows openssl +examples (push) Has been cancelled

And include it as key for connection reuse matching.

Reported-by: Stanislav Fort

Closes #22668
This commit is contained in:
Daniel Stenberg 2026-08-25 13:47:11 +02:00
parent 7ea37abc6a
commit 7be1e70cb6
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
6 changed files with 16 additions and 16 deletions

View file

@ -457,7 +457,7 @@ static CURLcode gtls_populate_creds(struct Curl_cfilter *cf,
}
infof(data, "SSL Trust Anchors:");
if(ssl_config->native_ca_store) {
if(config->native_ca_store) {
#ifdef USE_APPLE_SECTRUST
infof(data, " Native: Apple SecTrust");
creds_are_empty = FALSE;
@ -661,7 +661,7 @@ CURLcode Curl_gtls_client_trust_setup(struct Curl_cfilter *cf,
!conn_config->CApath &&
!conn_config->ca_info_blob &&
!ssl_config->primary.CRLfile &&
!ssl_config->native_ca_store &&
!conn_config->native_ca_store &&
!conn_config->clientcert; /* GnuTLS adds client cert to its credentials! */
if(cache_criteria_met)
@ -1604,7 +1604,7 @@ static CURLcode gtls_verify_cert(struct Curl_easy *data,
infof(data, " SSL certificate verified by GnuTLS");
#ifdef USE_APPLE_SECTRUST
if(!verified && ssl_config->native_ca_store) {
if(!verified && config->native_ca_store) {
CURLcode result =
Curl_vtls_apple_verify(cf, data, peer, chain->num_certs,
gtls_chain_get_der, chain, NULL, 0);

View file

@ -2999,7 +2999,6 @@ static CURLcode ossl_load_trust_anchors(struct Curl_cfilter *cf,
X509_STORE *store)
{
struct ssl_primary_config *conn_config = Curl_ssl_cf_get_primary_config(cf);
struct ssl_config_data *ssl_config = Curl_ssl_cf_get_config(cf, data);
CURLcode result = CURLE_OK;
const char * const ssl_cafile =
/* CURLOPT_CAINFO_BLOB overrides CURLOPT_CAINFO */
@ -3008,7 +3007,7 @@ static CURLcode ossl_load_trust_anchors(struct Curl_cfilter *cf,
bool have_native_check = FALSE;
octx->store_is_empty = TRUE;
if(ssl_config->native_ca_store) {
if(conn_config->native_ca_store) {
#ifdef USE_WIN32_CRYPTO
bool added = FALSE;
result = ossl_windows_load_anchors(cf, data, store, &added);
@ -3316,7 +3315,7 @@ CURLcode Curl_ssl_setup_x509_store(struct Curl_cfilter *cf,
!conn_config->CApath &&
!conn_config->ca_info_blob &&
!ssl_config->primary.CRLfile &&
!ssl_config->native_ca_store;
!conn_config->native_ca_store;
ERR_set_mark();
@ -3370,7 +3369,7 @@ static bool ossl_apply_session(
(SSL_get_verify_result(octx->ssl) != X509_V_OK)
#ifdef USE_APPLE_SECTRUST
/* if sectrust is used and verified the session before */
&& (!ssl_config->native_ca_store || !scs->sectrust_verified)
&& (!conn_cfg->native_ca_store || !scs->sectrust_verified)
#endif
) {
/* Session was from unverified connection, cannot reuse here */
@ -4835,7 +4834,7 @@ CURLcode Curl_ossl_check_peer_cert(struct Curl_cfilter *cf,
infof(data, "SSL certificate verified via OpenSSL.");
#ifdef USE_APPLE_SECTRUST
if(!verified && conn_config->verifypeer && ssl_config->native_ca_store) {
if(!verified && conn_config->verifypeer && conn_config->native_ca_store) {
/* we verify using Apple SecTrust *unless* OpenSSL already verified.
* This may happen if the application intercepted the OpenSSL callback
* and installed its own. */

View file

@ -1049,7 +1049,7 @@ static CURLcode cr_init_backend(struct Curl_cfilter *cf,
rustls_client_config_builder_dangerous_set_certificate_verifier(
config_builder, cr_verify_none);
}
else if(ssl_config->native_ca_store) {
else if(conn_config->native_ca_store) {
if(conn_config->CRLfile) {
failf(data, "rustls: CRL file not supported with native CA store; "
"the platform verifier has no CRL attachment API");

View file

@ -141,6 +141,7 @@ static bool match_ssl_primary_config(struct Curl_easy *data,
if((c1->version == c2->version) &&
(c1->version_max == c2->version_max) &&
(c1->ssl_options == c2->ssl_options) &&
(c1->native_ca_store == c2->native_ca_store) &&
(c1->verifypeer == c2->verifypeer) &&
(c1->verifyhost == c2->verifyhost) &&
(c1->verifystatus == c2->verifystatus) &&
@ -192,6 +193,7 @@ static bool clone_ssl_primary_config(struct ssl_primary_config *source,
dest->verifypeer = source->verifypeer;
dest->verifyhost = source->verifyhost;
dest->verifystatus = source->verifystatus;
dest->native_ca_store = source->native_ca_store;
dest->cache_session = source->cache_session;
dest->ssl_options = source->ssl_options;
@ -225,7 +227,7 @@ static void ssl_easy_config_compl_options(struct Curl_peer *origin,
/* If set via CURLOPT_(PROXY_)SSL_OPTIONS, we definitely use it.
* If not, we switch it on for supported backends if no custom
* CA settings exist. */
sslc->native_ca_store = !!(options & CURLSSLOPT_NATIVE_CA);
sslc->primary.native_ca_store = !!(options & CURLSSLOPT_NATIVE_CA);
sslc->enable_beast = !!(options & CURLSSLOPT_ALLOW_BEAST);
sslc->no_partialchain = !!(options & CURLSSLOPT_NO_PARTIALCHAIN);
sslc->no_revoke = !!(options & CURLSSLOPT_NO_REVOKE);
@ -256,7 +258,7 @@ CURLcode Curl_ssl_easy_config_complete(struct Curl_easy *data,
if(Curl_ssl_backend() != CURLSSLBACKEND_SCHANNEL) {
#if defined(USE_APPLE_SECTRUST) || defined(CURL_CA_NATIVE)
if(!sslc->custom_capath && !sslc->custom_cafile && !sslc->custom_cablob)
sslc->native_ca_store = TRUE;
sslc->primary.native_ca_store = TRUE;
#endif
#ifdef CURL_CA_PATH
if(!sslc->custom_capath && !CURL_EASY_STR(data, STRING_SSL_CAPATH)) {
@ -317,7 +319,7 @@ CURLcode Curl_ssl_easy_config_complete(struct Curl_easy *data,
if(Curl_ssl_backend() != CURLSSLBACKEND_SCHANNEL) {
#if defined(USE_APPLE_SECTRUST) || defined(CURL_CA_NATIVE)
if(!sslc->custom_capath && !sslc->custom_cafile && !sslc->custom_cablob)
sslc->native_ca_store = TRUE;
sslc->primary.native_ca_store = TRUE;
#endif
#ifdef CURL_CA_PATH
if(!sslc->custom_capath &&

View file

@ -54,6 +54,7 @@ struct ssl_primary_config {
BIT(verifypeer); /* set TRUE if this is desired */
BIT(verifyhost); /* set TRUE if CN/SAN must match hostname */
BIT(verifystatus); /* set TRUE if certificate status must be checked */
BIT(native_ca_store); /* use the native CA store of operating system */
BIT(cache_session); /* cache session or not */
BIT(deep_copy); /* members are deep copies, eg. owned here */
};
@ -70,7 +71,6 @@ struct ssl_config_data {
BIT(no_partialchain); /* do not accept partial certificate chains */
BIT(revoke_best_effort); /* ignore SSL revocation offline/missing revocation
list errors */
BIT(native_ca_store); /* use the native CA store of operating system */
BIT(auto_client_cert); /* automatically locate and use a client
certificate for authentication (Schannel) */
BIT(custom_cafile); /* application has set custom CA file */

View file

@ -592,7 +592,6 @@ static CURLcode wssl_populate_x509_store(struct Curl_cfilter *cf,
/* CURLOPT_CAINFO_BLOB overrides CURLOPT_CAINFO */
(ca_info_blob ? NULL : conn_config->CAfile);
const char * const ssl_capath = conn_config->CApath;
struct ssl_config_data *ssl_config = Curl_ssl_cf_get_config(cf, data);
bool imported_native_ca = FALSE;
bool imported_ca_info_blob = FALSE;
@ -601,7 +600,7 @@ static CURLcode wssl_populate_x509_store(struct Curl_cfilter *cf,
#ifndef NO_FILESYSTEM
/* load native CA certificates */
if(ssl_config->native_ca_store) {
if(conn_config->native_ca_store) {
#ifdef WOLFSSL_SYS_CA_CERTS
if(wolfSSL_CTX_load_system_CA_certs(wssl->ssl_ctx) != WOLFSSL_SUCCESS) {
infof(data, "error importing native CA store, continuing anyway");
@ -809,7 +808,7 @@ CURLcode Curl_wssl_setup_x509_store(struct Curl_cfilter *cf,
!conn_config->CApath &&
!conn_config->ca_info_blob &&
!ssl_config->primary.CRLfile &&
!ssl_config->native_ca_store;
!conn_config->native_ca_store;
cached_store = cache_criteria_met ? wssl_get_cached_x509_store(cf, data)
: NULL;