Blame SOURCES/gnupg-2.1.1-ocsp-keyusage.patch

e4fdbb
diff -up gnupg-2.1.1/sm/certlist.c.keyusage gnupg-2.1.1/sm/certlist.c
e4fdbb
--- gnupg-2.1.1/sm/certlist.c.keyusage	2014-11-27 11:51:36.000000000 +0100
e4fdbb
+++ gnupg-2.1.1/sm/certlist.c	2015-01-29 17:30:57.117135497 +0100
e4fdbb
@@ -146,10 +146,9 @@ cert_usage_p (ksba_cert_t cert, int mode
e4fdbb
 
e4fdbb
   if (mode == 5)
e4fdbb
     {
e4fdbb
-      if (use != ~0
e4fdbb
-          && (have_ocsp_signing
e4fdbb
-              || (use & (KSBA_KEYUSAGE_KEY_CERT_SIGN
e4fdbb
-                         |KSBA_KEYUSAGE_CRL_SIGN))))
e4fdbb
+      if (have_ocsp_signing
e4fdbb
+          || (use & (KSBA_KEYUSAGE_KEY_CERT_SIGN
e4fdbb
+                     |KSBA_KEYUSAGE_CRL_SIGN)))
e4fdbb
         return 0;
e4fdbb
       log_info (_("certificate should not have "
e4fdbb
                   "been used for OCSP response signing\n"));