In the PKINIT OpenSSL crypto code, use a signed int to hold the result of X509_get_ext_by_NID so we can detect negative return values. Reported by nalin at redhat.com. http://src.mit.edu/fisheye/changelog/krb5/?cs=24323 Commit By: ghudson Revision: 24323 Changed Files: U trunk/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c