Ludovic Courtès
bc3c41ce36
download: Verify TLS certificates unless asked not to.
Fixes <http://bugs.gnu.org/24466>.
Reported by Leo Famulari <leo@famulari.name>.
* guix/build/download.scm (%x509-certificate-directory): New variable.
(make-credendials-with-ca-trust-files, peer-certificate)
(assert-valid-server-certificate, print-tls-certificate-error): New
procedures. Add 'print-tls-certificate-error' as an exception printer
for 'tls-certificate-error'.
(tls-wrap): Add #:verify-certificate? parameter and honor it.
(open-connection-for-uri): Likewise.
(http-fetch): Likewise.
(url-fetch): Likewise.
* guix/download.scm (url-fetch)[builder]: Pass #:verify-certificate? #f.
* guix/scripts/lint.scm (probe-uri): Add case for 'tls-certificate-error'.
(validate-uri): Likewise.
* doc/guix.texi (Invoking guix download): Mention 'SSL_CERT_DIR'.
2016-11-07 23:39:01 +01:00
..
2016-09-03 10:36:20 +02:00
2016-10-08 21:20:35 +08:00
2016-10-10 21:40:23 +02:00
2015-03-31 22:43:01 +02:00
2016-04-01 00:05:42 +02:00
2016-11-07 23:39:01 +01:00
2016-06-27 09:30:01 +02:00
2015-07-08 10:53:05 +02:00
2016-01-05 00:28:42 +01:00
2015-09-11 20:24:30 +08:00
2016-02-09 11:39:30 +01:00
2015-03-31 22:43:01 +02:00
2016-10-17 23:59:03 +02:00
2015-04-23 18:52:40 +02:00
2016-01-19 18:01:07 -06:00
2016-06-15 17:02:18 +02:00
2016-10-08 21:20:35 +08:00
2015-03-31 22:43:01 +02:00
2015-05-27 22:36:52 +02:00
2016-09-29 23:59:06 +02:00
2016-10-13 15:27:16 -04:00
2016-08-30 22:38:28 +02:00
2015-08-31 15:39:34 +02:00
2013-05-08 23:45:02 +02:00
2016-08-30 10:31:48 +10:00
2014-09-04 23:24:54 +02:00
2016-07-03 18:55:30 +02:00
2016-09-06 11:12:11 +02:00
2016-05-23 18:05:46 +02:00
2015-10-29 17:30:18 -05:00
2015-03-31 22:43:01 +02:00