microsoft/msquic

Support in-memory certificate stores

Aberta

#4.951 aberto em 27 de mar. de 2025

 (2 comentários) (0 reação) (0 responsável)C (686 forks)github user discovery
Area: APIArea: Coreexternalfeature requestgood first issue

Métricas do repositório

Stars
 (4.764 estrelas)
Métricas de merge de PR
 (Mesclagem média 6d) (40 fundiu PRs em 30d)

Description

Describe the feature you'd like supported

I've been evaluating MsQuic and haven't used it, but already see a problem that would complicate usage: there isn't a way to use a certificate store that is in-memory. Custom certificate stores must be in a disk file. There are use cases where this is a problem.

Proposed solution

Both SChannel and OpenSSL can support this. See libcurl code:

SChannel: https://github.com/curl/curl/blob/0c20e9bf1a5cc7318f85e70212505856bb5f0e72/lib/vtls/schannel_verify.c#L122 OpenSSL: https://github.com/curl/curl/blob/0c20e9bf1a5cc7318f85e70212505856bb5f0e72/lib/vtls/openssl.c#L3021

I think this can already be done manually in SChannel using QUIC_CREDENTIAL_CONFIG::CertificateContext essentially the same way that libcurl does it.

Additional context

No response

Guia do colaborador