if (len > (sizeof(last->file_buf) - 1))
{
log_error(LOG_LEVEL_ERROR,
- "X509 PEM cert len %d is larger then buffer len %s",
+ "X509 PEM cert len %d is larger than buffer len %d",
len, sizeof(last->file_buf) - 1);
len = sizeof(last->file_buf) - 1;
}
else
{
csp->server_cert_verification_result = verify_result;
- log_error(LOG_LEVEL_ERROR, "SSL_get_verify_result failed: %s",
- X509_verify_cert_error_string(verify_result));
+ log_error(LOG_LEVEL_ERROR,
+ "X509 certificate verification for %s failed: %s",
+ csp->http->hostport, X509_verify_cert_error_string(verify_result));
ret = -1;
goto exit;
}
{
log_ssl_errors(LOG_LEVEL_ERROR,
"X509 subject name (code: %s, val: %s) error",
- CERT_PARAM_COMMON_NAME_FCODE, csp->http->host);
+ CERT_PARAM_ORGANIZATION_FCODE, csp->http->host);
ret = -1;
goto exit;
}
{
log_ssl_errors(LOG_LEVEL_ERROR,
"X509 subject name (code: %s, val: %s) error",
- CERT_PARAM_COMMON_NAME_FCODE, csp->http->host);
+ CERT_PARAM_ORG_UNIT_FCODE, csp->http->host);
ret = -1;
goto exit;
}
{
log_ssl_errors(LOG_LEVEL_ERROR,
"X509 subject name (code: %s, val: %s) error",
- CERT_PARAM_COMMON_NAME_FCODE, csp->http->host);
+ CERT_PARAM_COUNTRY_FCODE, csp->http->host);
ret = -1;
goto exit;
}
if (!X509_set_pubkey(cert, loaded_subject_key))
{
log_ssl_errors(LOG_LEVEL_ERROR,
- "Setting issuer name in signed certificate failed");
+ "Setting public key in signed certificate failed");
ret = -1;
goto exit;
}
if (!X509_set_subject_name(cert, subject_name))
{
log_ssl_errors(LOG_LEVEL_ERROR,
- "Setting issuer name in signed certificate failed");
+ "Setting subject name in signed certificate failed");
ret = -1;
goto exit;
}
if (!X509_set1_notBefore(cert, asn_time))
{
log_ssl_errors(LOG_LEVEL_ERROR,
- "Setting valid not befre in signed certificate failed");
+ "Setting valid not before in signed certificate failed");
ret = -1;
goto exit;
}
if (!set_x509_ext(cert, issuer_cert, NID_subject_key_identifier, CERTIFICATE_SUBJECT_KEY))
{
log_ssl_errors(LOG_LEVEL_ERROR,
- "Setting the Subject Key Identifie extension failed");
+ "Setting the Subject Key Identifier extension failed");
ret = -1;
goto exit;
}
if (!host_is_ip_address(csp->http->host) &&
!set_subject_alternative_name(cert, issuer_cert, csp->http->host))
{
- log_ssl_errors(LOG_LEVEL_ERROR, "Setting the Subject Alt Nameextension failed");
+ log_ssl_errors(LOG_LEVEL_ERROR,
+ "Setting the Subject Alt Name extension failed");
ret = -1;
goto exit;
}