Skip to content

Commit 8ed4c75

Browse files
authored
SNOW-1948906 Add logs to chain verification (#1315)
1 parent 69e2ad5 commit 8ed4c75

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

ocsp.go

+2
Original file line numberDiff line numberDiff line change
@@ -670,6 +670,8 @@ func verifyPeerCertificate(ctx context.Context, verifiedChains [][]*x509.Certifi
670670
for i := 0; i < len(verifiedChains); i++ {
671671
// Certificate signed by Root CA. This should be one before the last in the Certificate Chain
672672
numberOfNoneRootCerts := len(verifiedChains[i]) - 1
673+
logger.Tracef("checking cert, %v, %v, isCa: %v, rawIssuer: %v, rawSubject: %v", i, numberOfNoneRootCerts, verifiedChains[i][numberOfNoneRootCerts].IsCA, string(verifiedChains[i][numberOfNoneRootCerts].RawIssuer), string(verifiedChains[i][numberOfNoneRootCerts].RawSubject))
674+
logger.Tracef("checking cert, base64, rawIssuer: %v, rawSubject: %v", base64.StdEncoding.EncodeToString(verifiedChains[i][numberOfNoneRootCerts].RawIssuer), base64.StdEncoding.EncodeToString(verifiedChains[i][numberOfNoneRootCerts].RawSubject))
673675
if !verifiedChains[i][numberOfNoneRootCerts].IsCA || string(verifiedChains[i][numberOfNoneRootCerts].RawIssuer) != string(verifiedChains[i][numberOfNoneRootCerts].RawSubject) {
674676
// Check if the last Non Root Cert is also a CA or is self signed.
675677
// if the last certificate is not, add it to the list

0 commit comments

Comments
 (0)