From 96cfaf5051b503ff4475896549ad05a3d9a37691 Mon Sep 17 00:00:00 2001 From: stephb9959 Date: Wed, 13 Sep 2023 12:11:37 -0700 Subject: [PATCH] https://telecominfraproject.atlassian.net/browse/WIFI-7831 Signed-off-by: stephb9959 --- src/framework/SubSystemServer.cpp | 8 ++------ 1 file changed, 2 insertions(+), 6 deletions(-) diff --git a/src/framework/SubSystemServer.cpp b/src/framework/SubSystemServer.cpp index 47beff9..db4dc14 100644 --- a/src/framework/SubSystemServer.cpp +++ b/src/framework/SubSystemServer.cpp @@ -53,7 +53,6 @@ namespace OpenWifi { Context->useCertificate(Cert); Context->addChainCertificate(Root); - Context->addCertificateAuthority(Root); if (level_ == Poco::Net::Context::VERIFY_STRICT) { @@ -76,8 +75,7 @@ namespace OpenWifi { L.fatal(fmt::format("Wrong Certificate({}) for Key({})", cert_file_, key_file_)); } - SSL_CTX_set_verify(SSLCtx, SSL_VERIFY_PEER, nullptr); - + SSL_CTX_set_verify(SSLCtx, SSL_VERIFY_PEER, nullptr); if (level_ == Poco::Net::Context::VERIFY_STRICT) { SSL_CTX_set_client_CA_list(SSLCtx, SSL_load_client_CA_file(client_cas_.c_str())); } @@ -87,7 +85,7 @@ namespace OpenWifi { Context->enableSessionCache(); Context->setSessionCacheSize(0); Context->setSessionTimeout(60); - Context->enableExtendedCertificateVerification(true); + Context->enableExtendedCertificateVerification( level_!= Poco::Net::Context::VERIFY_NONE ); Context->disableStatelessSessionResumption(); } @@ -320,8 +318,6 @@ namespace OpenWifi { } else if (L == "once") M = Poco::Net::Context::VERIFY_ONCE; - std::cout << "Security level: " << level << " : " << L << " : " << M << std::endl; - PropertiesFileServerEntry entry( MicroServiceConfigGetString(address, ""), MicroServiceConfigGetInt(port, 0), MicroServiceConfigPath(key, ""), MicroServiceConfigPath(cert, ""),