]> Cypherpunks repositories - gostls13.git/commit
crypto/x509: check for new tls-ca-bundle.pem last
authorRuss Cox <rsc@golang.org>
Tue, 7 Feb 2017 16:59:38 +0000 (11:59 -0500)
committerRuss Cox <rsc@golang.org>
Tue, 7 Feb 2017 17:19:05 +0000 (17:19 +0000)
commit1ead0bd1dc8958939b16b8fc3ab2cc8242f5e831
tree527195c05f44ebcbb4f10089fb3fb7b0f26713c1
parent99df7c9caa19d99747c4766be171c9487c9645cf
crypto/x509: check for new tls-ca-bundle.pem last

We added CentOS 7's /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
to the list in response to #17549 - not being able to find any certs otherwise.

Now we have #18813, where CentOS 6 apparently has both that file
and /etc/pki/tls/certs/ca-bundle.crt, and the latter is complete while
the former is not.

Moving the new CentOS 7 file to the bottom of the list should fix both
problems: the CentOS 7 system that didn't have any of the other files
in the list will still find the new one, and existing systems will still
keep using what they were using instead of preferring the new path
that may or may not be complete on some systems.

Fixes #18813.

Change-Id: I5275ab67424b95e7210e14938d3e986c8caee0ba
Reviewed-on: https://go-review.googlesource.com/36429
Run-TryBot: Russ Cox <rsc@golang.org>
Reviewed-by: Adam Langley <agl@golang.org>
src/crypto/x509/root_linux.go