it is done for CERT_AS_INHERIT.
Without this inheritance of IP address resources does not work. Problem
noticed by Ties de Kock (tdekock (at) ripe.net)
OK job@ tb@ benno@
-/* $OpenBSD: validate.c,v 1.60 2023/05/09 10:34:32 tb Exp $ */
+/* $OpenBSD: validate.c,v 1.61 2023/05/11 14:05:31 claudio Exp $ */
/*
* Copyright (c) 2019 Kristaps Dzonsons <kristaps@bsd.lv>
*
}
for (i = 0; i < cert->ipsz; i++) {
+ if (cert->ips[i].type == CERT_IP_INHERIT)
+ continue;
if (valid_ip(a, cert->ips[i].afi, cert->ips[i].min,
cert->ips[i].max))
continue;