From: Filippo Valsorda Date: Sat, 16 Dec 2017 13:35:52 +0000 (-0400) Subject: crypto/tls: document VerifyPeerCertificate behavior in relation to ClientAuth X-Git-Tag: go1.10beta2~77 X-Git-Url: http://www.git.cypherpunks.su/?a=commitdiff_plain;h=92b142a653afb8bd43bc172b08f667591c89ff3e;p=gostls13.git crypto/tls: document VerifyPeerCertificate behavior in relation to ClientAuth Change-Id: I3ff478912a5a178492d544d2f4ee9cc7570d9acc Reviewed-on: https://go-review.googlesource.com/84475 Reviewed-by: Filippo Valsorda Reviewed-by: Brad Fitzpatrick --- diff --git a/src/crypto/tls/common.go b/src/crypto/tls/common.go index d4b0286b85..646b107958 100644 --- a/src/crypto/tls/common.go +++ b/src/crypto/tls/common.go @@ -406,8 +406,9 @@ type Config struct { // // If normal verification fails then the handshake will abort before // considering this callback. If normal verification is disabled by - // setting InsecureSkipVerify then this callback will be considered but - // the verifiedChains argument will always be nil. + // setting InsecureSkipVerify, or (for a server) when ClientAuth is + // RequestClientCert or RequireAnyClientCert, then this callback will + // be considered but the verifiedChains argument will always be nil. VerifyPeerCertificate func(rawCerts [][]byte, verifiedChains [][]*x509.Certificate) error // RootCAs defines the set of root certificate authorities