How can we tell a CFStream to use a set of anchor certificates?

青春壹個敷衍的年華 提交于 2019-12-06 15:18:38

eskimo1 from Apple Devforums answered this so:

First, disable automatic trust evaluation using kCFStreamSSLValidatesCertificateChain.

Second, once the stream is up and running (I typically do this in my 'can accept bytes' or 'has bytes available' message handling), get the SecTrust object from the stream using kCFStreamPropertySSLPeerTrust and evaluate that trust for yourself. If the trust evaluation fails, tear down the stream.

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!