Package: wl
Version: 2.10.1+0.20040728-2
Severity: wishlist

Setting ssl-certificate-verification-policy to 3 doesn't reject SSL
connection even if verification fails.

ssl.el uses openssl.  But the bug is in openssl.  The -verify
option of s_client doesn't exit if the server verification fails.
(ref. `http://bugs.debian.org/210757')

This problem is not yet solved in the upstream.

-- 
Tatsuya Kinoshita

Attachment: pgpL9qHnCkmFu.pgp
Description: PGP signature

Reply via email to