Ludovic Courtès
bc3c41ce36
download: Verify TLS certificates unless asked not to.
Fixes <http://bugs.gnu.org/24466>.
Reported by Leo Famulari <leo@famulari.name>.
* guix/build/download.scm (%x509-certificate-directory): New variable.
(make-credendials-with-ca-trust-files, peer-certificate)
(assert-valid-server-certificate, print-tls-certificate-error): New
procedures. Add 'print-tls-certificate-error' as an exception printer
for 'tls-certificate-error'.
(tls-wrap): Add #:verify-certificate? parameter and honor it.
(open-connection-for-uri): Likewise.
(http-fetch): Likewise.
(url-fetch): Likewise.
* guix/download.scm (url-fetch)[builder]: Pass #:verify-certificate? #f.
* guix/scripts/lint.scm (probe-uri): Add case for 'tls-certificate-error'.
(validate-uri): Likewise.
* doc/guix.texi (Invoking guix download): Mention 'SSL_CERT_DIR'.
2016-11-07 23:39:01 +01:00
..
2015-11-03 18:05:43 -05:00
2016-09-20 23:22:42 +09:00
2016-10-19 15:54:10 +02:00
2016-10-19 15:54:10 +02:00
2016-10-17 23:59:02 +02:00
2016-07-14 19:07:07 +02:00
2015-11-01 18:20:04 -05:00
2016-10-19 15:54:10 +02:00
2016-08-19 17:34:37 +02:00
2016-08-28 16:22:19 +02:00
2016-07-16 14:41:39 +02:00
2016-10-15 23:46:39 +02:00
2016-10-28 22:30:17 +02:00
2016-05-17 14:02:48 +02:00
2016-11-07 23:39:01 +01:00
2016-10-19 15:54:10 +02:00
2016-11-06 18:08:53 +01:00
2016-10-19 15:54:10 +02:00
2015-10-27 00:01:20 +01:00
2016-10-19 15:54:10 +02:00
2016-07-29 22:32:04 +02:00
2016-10-19 15:54:10 +02:00
2016-11-06 18:08:53 +01:00