Added a cert_policy option to conftest configurations
This commit is contained in:
@@ -247,7 +247,7 @@ static peer_cfg_t *load_peer_config(private_config_t *this,
|
|||||||
child_cfg_t *child_cfg;
|
child_cfg_t *child_cfg;
|
||||||
enumerator_t *enumerator;
|
enumerator_t *enumerator;
|
||||||
identification_t *lid, *rid;
|
identification_t *lid, *rid;
|
||||||
char *child;
|
char *child, *policy;
|
||||||
uintptr_t strength;
|
uintptr_t strength;
|
||||||
|
|
||||||
ike_cfg = load_ike_config(this, settings, config);
|
ike_cfg = load_ike_config(this, settings, config);
|
||||||
@@ -276,6 +276,11 @@ static peer_cfg_t *load_peer_config(private_config_t *this,
|
|||||||
{
|
{
|
||||||
auth->add(auth, AUTH_RULE_ECDSA_STRENGTH, strength);
|
auth->add(auth, AUTH_RULE_ECDSA_STRENGTH, strength);
|
||||||
}
|
}
|
||||||
|
policy = settings->get_str(settings, "configs.%s.cert_policy", NULL, config);
|
||||||
|
if (policy)
|
||||||
|
{
|
||||||
|
auth->add(auth, AUTH_RULE_CERT_POLICY, strdup(policy));
|
||||||
|
}
|
||||||
auth->add(auth, AUTH_RULE_IDENTITY, rid);
|
auth->add(auth, AUTH_RULE_IDENTITY, rid);
|
||||||
peer_cfg->add_auth_cfg(peer_cfg, auth, FALSE);
|
peer_cfg->add_auth_cfg(peer_cfg, auth, FALSE);
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user