OCSP_BASICRESP bs contains no certificates.
From David von Oheimb (OpenSSL
121738d1)
ok beck
-/* $OpenBSD: ocsp_vfy.c,v 1.18 2021/11/24 19:29:19 tb Exp $ */
+/* $OpenBSD: ocsp_vfy.c,v 1.19 2021/11/24 19:33:24 tb Exp $ */
/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
* project 2000.
*/
goto end;
}
}
- } else
+ } else if (certs != NULL) {
+ untrusted = certs;
+ } else {
untrusted = bs->certs;
+ }
init_res = X509_STORE_CTX_init(&ctx, st, signer, untrusted);
if (!init_res) {
ret = -1;