Blame SOURCES/gnupg-2.0.20-ocsp-keyusage.patch

9f54a2
diff -up gnupg-2.0.20/sm/certlist.c.keyusage gnupg-2.0.20/sm/certlist.c
9f54a2
--- gnupg-2.0.20/sm/certlist.c.keyusage	2013-05-10 14:55:49.000000000 +0200
9f54a2
+++ gnupg-2.0.20/sm/certlist.c	2013-05-15 14:15:57.420276618 +0200
9f54a2
@@ -146,10 +146,9 @@ cert_usage_p (ksba_cert_t cert, int mode
9f54a2
 
9f54a2
   if (mode == 5)
9f54a2
     {
9f54a2
-      if (use != ~0 
9f54a2
-          && (have_ocsp_signing
9f54a2
-              || (use & (KSBA_KEYUSAGE_KEY_CERT_SIGN
9f54a2
-                         |KSBA_KEYUSAGE_CRL_SIGN))))
9f54a2
+      if (have_ocsp_signing
9f54a2
+          || (use & (KSBA_KEYUSAGE_KEY_CERT_SIGN
9f54a2
+                     |KSBA_KEYUSAGE_CRL_SIGN)))
9f54a2
         return 0;
9f54a2
       log_info (_("certificate should not have "
9f54a2
                   "been used for OCSP response signing\n"));