microsoft/msquic

Support in-memory certificate stores

Aperta

#4951 aperta il 27 mar 2025

 (2 commenti) (0 reazioni) (0 assegnatari)C (686 fork)github user discovery
Area: APIArea: Coreexternalfeature requestgood first issue

Metriche repository

Star
 (4764 stelle)
Metriche merge PR
 (Merge medio 6g) (40 PR mergiate in 30 g)

Descrizione

Describe the feature you'd like supported

I've been evaluating MsQuic and haven't used it, but already see a problem that would complicate usage: there isn't a way to use a certificate store that is in-memory. Custom certificate stores must be in a disk file. There are use cases where this is a problem.

Proposed solution

Both SChannel and OpenSSL can support this. See libcurl code:

SChannel: https://github.com/curl/curl/blob/0c20e9bf1a5cc7318f85e70212505856bb5f0e72/lib/vtls/schannel_verify.c#L122 OpenSSL: https://github.com/curl/curl/blob/0c20e9bf1a5cc7318f85e70212505856bb5f0e72/lib/vtls/openssl.c#L3021

I think this can already be done manually in SChannel using QUIC_CREDENTIAL_CONFIG::CertificateContext essentially the same way that libcurl does it.

Additional context

No response

Guida contributor