]> Cypherpunks repositories - gostls13.git/commit
crypto/tls: revalidate whole chain on resumption on Windows and macOS
authorFilippo Valsorda <filippo@golang.org>
Fri, 30 Jan 2026 17:07:23 +0000 (18:07 +0100)
committerGopher Robot <gobot@golang.org>
Tue, 3 Feb 2026 18:34:45 +0000 (10:34 -0800)
commitb691a2edc7f5863f61a07c4a4f087eef1a15a704
tree350ed19cf98272a8cadd6a4eeda48dccc899f7cd
parent31c9bcb1037a332fd547808693cd1899090b5854
crypto/tls: revalidate whole chain on resumption on Windows and macOS

TestHandshakeChangeRootCAsResumption and TestHandshakeGetConfigForClientDifferentClientCAs
changed because previously rootA and rootB shared Subject and SPKI,
which made the new full-chain revalidation check succeed, as the
same leaf would verify against both roots.

Fixes #77376

Cq-Include-Trybots: luci.golang.try:gotip-darwin-arm64-longtest
Change-Id: I60bed694bdc621c9e83f1bd8a8224c016a6a6964
Reviewed-on: https://go-review.googlesource.com/c/go/+/741361
Auto-Submit: Filippo Valsorda <filippo@golang.org>
Reviewed-by: Dmitri Shuralyov <dmitshur@google.com>
Reviewed-by: Roland Shoemaker <roland@golang.org>
LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Auto-Submit: Roland Shoemaker <roland@golang.org>
src/crypto/tls/common.go
src/crypto/tls/handshake_server_test.go
src/crypto/tls/tls_test.go