ssl: Improve error message in cert chain verification

It contains the same information as before, but should be more readable.
This commit is contained in:
Christophe Fergeau 2013-09-20 17:07:34 +02:00
parent 7e8ba10779
commit b34169feb6

View File

@ -424,8 +424,8 @@ static int openssl_verify(int preverify_ok, X509_STORE_CTX *ctx)
err = X509_STORE_CTX_get_error(ctx);
if (depth > 0) {
if (!preverify_ok) {
spice_warning("openssl verify:num=%d:%s:depth=%d:%s", err,
X509_verify_cert_error_string(err), depth, buf);
spice_warning("Error in certificate chain verification: %s (num=%d:depth%d:%s)",
X509_verify_cert_error_string(err), err, depth, buf);
v->all_preverify_ok = 0;
/* if certificate verification failed, we can still authorize the server */