microsoft/msquic

Support in-memory certificate stores

Ouverte

#4 951 ouverte le 27 mars 2025

 (2 commentaires) (0 réaction) (0 personne assignée)C (686 forks)github user discovery
Area: APIArea: Coreexternalfeature requestgood first issue

Métriques du dépôt

Stars
 (4 764 étoiles)
Métriques de merge PR
 (Merge moyen 6j) (40 PRs mergées en 30 j)

Description

Describe the feature you'd like supported

I've been evaluating MsQuic and haven't used it, but already see a problem that would complicate usage: there isn't a way to use a certificate store that is in-memory. Custom certificate stores must be in a disk file. There are use cases where this is a problem.

Proposed solution

Both SChannel and OpenSSL can support this. See libcurl code:

SChannel: https://github.com/curl/curl/blob/0c20e9bf1a5cc7318f85e70212505856bb5f0e72/lib/vtls/schannel_verify.c#L122 OpenSSL: https://github.com/curl/curl/blob/0c20e9bf1a5cc7318f85e70212505856bb5f0e72/lib/vtls/openssl.c#L3021

I think this can already be done manually in SChannel using QUIC_CREDENTIAL_CONFIG::CertificateContext essentially the same way that libcurl does it.

Additional context

No response

Guide contributeur