[gnutls-devel] gnutls-cli --dane

Nikos Mavrogiannopoulos nmav at gnutls.org
Mon Apr 28 11:42:02 CEST 2014


On Fri, Apr 18, 2014 at 9:19 PM, James Cloos <cloos at jhcloos.com> wrote:

> DANE says that verification succeeds if any of the TLSA records match.
> That language was chosen expressly to permit secure rollovers.

Hello,
 There was a patch in
https://savannah.gnu.org/support/?func=detailitem&item_id=108549
that should fix the issue you mention. It is now applied.

regards,
Nikos



More information about the Gnutls-devel mailing list