Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

p11-kit export-object should support exporting certificate with attached extensions #565

Open
ueno opened this issue Sep 20, 2023 · 0 comments

Comments

@ueno
Copy link
Member

ueno commented Sep 20, 2023

p11-kit allows certificate extensions stored as a separate object as CKO_X_CERTIFICATE_EXTENSION, which can be later attached to CKO_CERTIFICATE. This makes it easy for administrators to put additional constraints to the certificate, as described in:
https://nikmav.blogspot.com/2016/06/restricting-scope-of-ca-certificates.html

p11tool (GnuTLS) provides --export-stapled option to export a certificate with all such extensions attached. p11-kit export-object could also support that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant