The OCSP responder URI included within an X.509 certificate may or may not include a trailing slash. We currently rely on the fact that format_uri() incorrectly inserts an initial slash, which we include unconditionally within the OCSP request URI. Switch to using uri_encode() directly, and insert a slash only if the X.509 certificate's OCSP responder URI does not already include a trailing slash. Signed-off-by: Michael Brown <mcb30@ipxe.org>tags/v1.20.1
|
|
||
209 |
|
209 |
|
210 |
|
210 |
|
211 |
|
211 |
|
212 |
|
|
|
213 |
|
|
|
214 |
|
|
|
215 |
|
|
|
|
212 |
|
|
|
213 |
|
|
|
214 |
|
|
|
215 |
|
|
216 |
|
216 |
|
217 |
|
217 |
|
218 |
|
218 |
|
|
|
||
224 |
|
224 |
|
225 |
|
225 |
|
226 |
|
226 |
|
227 |
|
|
|
228 |
|
|
|
229 |
|
|
|
230 |
|
|
|
231 |
|
|
|
|
227 |
|
|
|
228 |
|
|
|
229 |
|
|
|
230 |
|
|
|
231 |
|
|
|
232 |
|
|
|
233 |
|
|
232 |
|
234 |
|
233 |
|
|
|
|
235 |
|
|
234 |
|
236 |
|
235 |
|
237 |
|
236 |
|
|
|
|
238 |
|
|
237 |
|
239 |
|
238 |
|
|
|
239 |
|
|
|
240 |
|
|
|
241 |
|
|
|
242 |
|
|
|
243 |
|
|
|
244 |
|
|
|
245 |
|
|
|
|
240 |
|
|
|
241 |
|
|
|
242 |
|
|
246 |
|
243 |
|
247 |
|
|
|
248 |
|
|
|
|
244 |
|
|
|
245 |
|
|
249 |
|
246 |
|
250 |
|
247 |
|
251 |
|
248 |
|
252 |
|
|
|
|
249 |
|
|
253 |
|
250 |
|
254 |
|
251 |
|
255 |
|
|
|
|
252 |
|
|
|
253 |
|
|
|
254 |
|
|
|
255 |
|
|
256 |
|
256 |
|
257 |
|
257 |
|
258 |
|
258 |
|
259 |
|
259 |
|
260 |
|
260 |
|
261 |
|
261 |
|
262 |
|
|
|
263 |
|
|
|
264 |
|
|
|
265 |
|
|
|
266 |
|
|
|
|
262 |
|
|
|
263 |
|
|
|
264 |
|
|
267 |
|
265 |
|
268 |
|
266 |
|
269 |
|
267 |
|