• src/xptls/TODO.mdsrc/xptls/xp_ca_botan3.cpp

    From Deucе@VERT to Git commit to main/sbbs/master on Wed Aug 5 18:01:48 2026
    https://gitlab.synchro.net/main/sbbs/-/commit/06d8afd45fc1e6df42bb6072
    Added Files:
    src/xptls/TODO.md
    Modified Files:
    src/xptls/xp_ca_botan3.cpp
    Log Message:
    xptls: retain Botan 3.11 compatibility

    xptls advertises support for Botan 3.6 and newer, but the new CA
    implementation used IP address headers and strict decoder limits added in
    Botan 3.12. This prevented FreeBSD CI with Botan 3.11.1 from compiling
    the provider.

    Decode IP subjectAltName values from their standard extension encoding so
    both IPv4 and IPv6 remain available without the newer convenience APIs.
    Use the compatible BER decoder constructor for PKCS#7 input.

    Document the compatibility code, the prospective Botan 3.13 minimum,
    and the CRL validation follow-up tracked by Botan issue 5784.

    Co-Authored-By: OpenAI Codex <noreply@openai.com>

    ---
    ■ Synchronet ■ Vertrauen ■ Home of Synchronet ■ [vert/cvs/bbs].synchro.net