]> Cypherpunks repositories - gostls13.git/commit
[release-branch.go1.25] crypto/tls: revalidate whole chain on resumption on Windows...
authorFilippo Valsorda <filippo@golang.org>
Fri, 30 Jan 2026 17:07:23 +0000 (18:07 +0100)
committerGopher Robot <gobot@golang.org>
Tue, 3 Feb 2026 19:17:48 +0000 (11:17 -0800)
commit451201453075da6314c24aa96b35ce1cc8260366
treeeda9ef99d5dc48fb5bd1cbcd6a42d57197a2985b
parentd5987bff8ab92b4d96667ca960faeb92b97d5e75
[release-branch.go1.25] crypto/tls: revalidate whole chain on resumption on Windows and macOS

TestHandshakeChangeRootCAsResumption and TestHandshakeGetConfigForClientDifferentClientCAs
changed because previously rootA and rootB shared Subject and SPKI,
which made the new full-chain revalidation check succeed, as the
same leaf would verify against both roots.

Updates #77376
Fixes #77425

Cq-Include-Trybots: luci.golang.try:go1.25-darwin-arm64-longtest
Change-Id: I60bed694bdc621c9e83f1bd8a8224c016a6a6964
Reviewed-on: https://go-review.googlesource.com/c/go/+/741361
Auto-Submit: Filippo Valsorda <filippo@golang.org>
Reviewed-by: Dmitri Shuralyov <dmitshur@google.com>
Reviewed-by: Roland Shoemaker <roland@golang.org>
LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Auto-Submit: Roland Shoemaker <roland@golang.org>
(cherry picked from commit b691a2edc7f5863f61a07c4a4f087eef1a15a704)
Reviewed-on: https://go-review.googlesource.com/c/go/+/741246
Reviewed-by: Michael Pratt <mpratt@google.com>
Auto-Submit: Michael Pratt <mpratt@google.com>
src/crypto/tls/common.go
src/crypto/tls/handshake_server_test.go
src/crypto/tls/tls_test.go