Blame SOURCES/rsyslog-8.1911.0-rhbz1782353-deny-expired-by-default.patch

108b33
From 0de93c9e1597b20f71bb61d5375ded546cfd2fa8 Mon Sep 17 00:00:00 2001
108b33
From: Jiri Vymazal <jvymazal@redhat.com>
108b33
Date: Wed, 11 Dec 2019 15:35:26 +0100
108b33
Subject: [PATCH] Changed default for permitExpiredCerts to "off"
108b33
108b33
This is to be conssitent with rsyslog's prior behavior where
108b33
expired certs were automatically rejected
108b33
---
108b33
 runtime/nsd_gtls.c | 10 +++++-----
108b33
 runtime/nsd_ossl.c |  8 ++++----
108b33
 2 files changed, 9 insertions(+), 9 deletions(-)
108b33
108b33
diff --git a/runtime/nsd_gtls.c b/runtime/nsd_gtls.c
108b33
index 5df12994d1..2be0ca9c92 100644
108b33
--- a/runtime/nsd_gtls.c
108b33
+++ b/runtime/nsd_gtls.c
108b33
@@ -1461,16 +1461,16 @@ SetPermitExpiredCerts(nsd_t *pNsd, uchar *mode)
108b33
 	nsd_gtls_t *pThis = (nsd_gtls_t*) pNsd;
108b33
 
108b33
 	ISOBJ_TYPE_assert((pThis), nsd_gtls);
108b33
-	/* default is set to warn! */
108b33
-	if(mode == NULL || !strcasecmp((char*)mode, "warn")) {
108b33
-		pThis->permitExpiredCerts = GTLS_EXPIRED_WARN;
108b33
-	} else if(!strcasecmp((char*) mode, "off")) {
108b33
+	/* default is set to off! */
108b33
+	if(mode == NULL || !strcasecmp((char*)mode, "off")) {
108b33
 		pThis->permitExpiredCerts = GTLS_EXPIRED_DENY;
108b33
+	} else if(!strcasecmp((char*) mode, "warn")) {
108b33
+		pThis->permitExpiredCerts = GTLS_EXPIRED_WARN;
108b33
 	} else if(!strcasecmp((char*) mode, "on")) {
108b33
 		pThis->permitExpiredCerts = GTLS_EXPIRED_PERMIT;
108b33
 	} else {
108b33
 		LogError(0, RS_RET_VALUE_NOT_SUPPORTED, "error: permitexpiredcerts mode '%s' not supported by "
108b33
-				"ossl netstream driver", mode);
108b33
+				"gtls netstream driver", mode);
108b33
 		ABORT_FINALIZE(RS_RET_VALUE_NOT_SUPPORTED);
108b33
 	}
108b33
 
108b33
diff --git a/runtime/nsd_ossl.c b/runtime/nsd_ossl.c
108b33
index 4f8dd845ab..ebb2537d72 100644
108b33
--- a/runtime/nsd_ossl.c
108b33
+++ b/runtime/nsd_ossl.c
108b33
@@ -1130,11 +1130,11 @@ SetPermitExpiredCerts(nsd_t *pNsd, uchar *mode)
108b33
 	nsd_ossl_t *pThis = (nsd_ossl_t*) pNsd;
108b33
 
108b33
 	ISOBJ_TYPE_assert((pThis), nsd_ossl);
108b33
-	/* default is set to warn! */
108b33
-	if(mode == NULL || !strcasecmp((char*)mode, "warn")) {
108b33
-		pThis->permitExpiredCerts = OSSL_EXPIRED_WARN;
108b33
-	} else if(!strcasecmp((char*) mode, "off")) {
108b33
+	/* default is set to off! */
108b33
+	if(mode == NULL || !strcasecmp((char*)mode, "off")) {
108b33
 		pThis->permitExpiredCerts = OSSL_EXPIRED_DENY;
108b33
+	} else if(!strcasecmp((char*) mode, "warn")) {
108b33
+		pThis->permitExpiredCerts = OSSL_EXPIRED_WARN;
108b33
 	} else if(!strcasecmp((char*) mode, "on")) {
108b33
 		pThis->permitExpiredCerts = OSSL_EXPIRED_PERMIT;
108b33
 	} else {