+ // Pick up any valid CRLs inline.
+ const vector<XSECCryptoX509CRL*>& crls = pkixParams->getCRLs();
+ for (vector<XSECCryptoX509CRL*>::const_iterator j=crls.begin(); j!=crls.end(); ++j) {
+ if ((*j)->getProviderName()==DSIGConstants::s_unicodeStrPROVOpenSSL &&
+ (X509_cmp_time(X509_CRL_get_nextUpdate(static_cast<OpenSSLCryptoX509CRL*>(*j)->getOpenSSLX509CRL()), &now) > 0)) {
+ string crlissuer(X509_NAME_to_string(X509_CRL_get_issuer(static_cast<OpenSSLCryptoX509CRL*>(*j)->getOpenSSLX509CRL())));
+ if (crlissuer.empty() || crlissuers.count(crlissuer)) {
+ // We already have a CRL for this cert, so skip this one.
+ continue;
+ }
+ m_log.debug("added CRL issued by (%s)", crlissuer.c_str());
+ crlissuers.insert(crlissuer);
+ // owned by store
+ X509_STORE_add_crl(store, X509_CRL_dup(static_cast<OpenSSLCryptoX509CRL*>(*j)->getOpenSSLX509CRL()));
+ }
+ }
+