Wildcard|Strict] * [`host] Domain_name.t (Certificate.Host_set.t) reported by @mmaker in #88, fixed in #127RSA|ECDSA] * Nocrypto.Hash.hash) option requested by @psafont in #123, fixed in #128revert General_name.t (DNS and IP components) to string/Cstruct.t list
fingerprint : t -> hash -> Cstruct.t, the hash of the certificate (@cfcs, #66)Authenticator.chain_of_trust are not validated (to contain KeyUsage / BasicConstraint extensions) anymore, users can use valid_ca and valid_cas to filter CAs upfrontOk of certificate option | Fail of certificate_failureOk of certificate | Fail of certificate_failure ], where [certificate] is the trust anchor