Hi,
alright, there is no common rule, but a few quite common rules (call it best practice). It would really be good to have them somewhere in a common library.
For the callback: How can I find out for which part of the certificate chain the callback is called? If I only want to verify the actual server certificate? How do I work with this c-style certificate store? Maybe it is enough, but maybe not.
Christopher
(1)
]
