Hide Forgot
It was reported that openssl verify function ignores X509_V_ERR_INVALID_PURPOSE in its verify callback when verifying root and intermediate certificates with extended key usage extension.
Created attachment 1127332 [details] Proposed upstream patch 1
Created attachment 1127333 [details] Proposed upstream patch 2
Created attachment 1127335 [details] Proposed upstream patch 3
Created attachment 1127336 [details] Proposed upstream patch 4
This patch was applied to upstream master branch to fix this issue: https://github.com/openssl/openssl/commit/33cc5dde478ba5ad79f8fd4acd8737f0e60e236e