microsoft/msquic

Support in-memory certificate stores

Offen

#4.951 geöffnet am 27.03.2025

 (2 Kommentare) (0 Reaktionen) (0 zugewiesene Personen)C (686 Forks)github user discovery
Area: APIArea: Coreexternalfeature requestgood first issue

Repository-Metriken

Stars
 (4.764 Sterne)
PR-Merge-Metriken
 (Durchschn. Merge 6T) (40 gemergte PRs in 30 T)

Beschreibung

Describe the feature you'd like supported

I've been evaluating MsQuic and haven't used it, but already see a problem that would complicate usage: there isn't a way to use a certificate store that is in-memory. Custom certificate stores must be in a disk file. There are use cases where this is a problem.

Proposed solution

Both SChannel and OpenSSL can support this. See libcurl code:

SChannel: https://github.com/curl/curl/blob/0c20e9bf1a5cc7318f85e70212505856bb5f0e72/lib/vtls/schannel_verify.c#L122 OpenSSL: https://github.com/curl/curl/blob/0c20e9bf1a5cc7318f85e70212505856bb5f0e72/lib/vtls/openssl.c#L3021

I think this can already be done manually in SChannel using QUIC_CREDENTIAL_CONFIG::CertificateContext essentially the same way that libcurl does it.

Additional context

No response

Contributor Guide