tree 4a1112e7adff6516e4e2d6e590390b10cdae14f6
parent e6fd36993cde9c69fbf496f5b15d4d5f2cbe3862
author David Benjamin <davidben@google.com> 1740179421 -0500
committer Boringssl LUCI CQ <boringssl-scoped@luci-project-accounts.iam.gserviceaccount.com> 1740685886 -0800

Iterate on SSL_CREDENTIAL_set_must_match_issuer a bit

First, simplify the API a bit:
- Just take a boolean param rather than having both set and clear
  functions.
- Unless we need it, no need to bother with a getter. We generally
  assume that the caller knows what they configured.

Next, expand on the docs and move it with other credential APIs, not
SSL_PRIVATE_KEY_METHOD.

Finally, fix a bug and test this in runner: the TLS 1.2 handshake forgot
to check the issuer, which meant that it assumed all credentials were
viable. Fix this and add tests to cover it all. In doing so, this pulls
in the MustMatchIssuer runner plumbing out of
https://boringssl-review.googlesource.com/c/boringssl/+/73087 to land a
little sooner.

Also test that issuer matching works with delegated credentials. May as
well.

Change-Id: I22aee148dd81fb9804d80b4243b68a5ecdead480
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/76708
Reviewed-by: Adam Langley <agl@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
