Uploaded image for project: 'CouchDB'
  1. CouchDB
  2. COUCHDB-840

be more relaxed about verifying SSL certificate chains

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 1.0
    • 1.0.1
    • None
    • None

    Description

      The new Erlang SSL implementation (which we use to consume _changes) has a default verification depth of 1. This causes pull replication from an SSL-wrapped server to fail if the server has an intermediate certificate in its chain. Intermediate certificates are pretty common especially at the cheaper end, e.g. GoDaddy certs. OpenSSL uses a default depth of 9; I think we should do the same.

      Attachments

        1. COUCHDB-840.patch
          0.6 kB
          Adam Kocoloski

        Activity

          People

            Unassigned Unassigned
            kocolosk Adam Kocoloski
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Slack

                Issue deployment