pki: Print and document the name constraint type for DNS or email constraints
As email constraints may be for a specific host, it is not clear from the name itself if it is a DNS or email constraint.
This commit is contained in:
@@ -65,6 +65,22 @@ static void print_key(private_key_t *key)
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Get a prefix for a named constraint identity type
|
||||
*/
|
||||
static char* get_type_pfx(identification_t *id)
|
||||
{
|
||||
switch (id->get_type(id))
|
||||
{
|
||||
case ID_RFC822_ADDR:
|
||||
return "email:";
|
||||
case ID_FQDN:
|
||||
return "dns:";
|
||||
default:
|
||||
return "";
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Print X509 specific certificate information
|
||||
*/
|
||||
@@ -202,7 +218,7 @@ static void print_x509(x509_t *x509)
|
||||
printf("Permitted NameConstraints:\n");
|
||||
first = FALSE;
|
||||
}
|
||||
printf(" %Y\n", id);
|
||||
printf(" %s%Y\n", get_type_pfx(id), id);
|
||||
}
|
||||
enumerator->destroy(enumerator);
|
||||
first = TRUE;
|
||||
@@ -214,7 +230,7 @@ static void print_x509(x509_t *x509)
|
||||
printf("Excluded NameConstraints:\n");
|
||||
first = FALSE;
|
||||
}
|
||||
printf(" %Y\n", id);
|
||||
printf(" %s%Y\n", get_type_pfx(id), id);
|
||||
}
|
||||
enumerator->destroy(enumerator);
|
||||
|
||||
|
||||
@@ -147,10 +147,22 @@ times.
|
||||
Set path length constraint.
|
||||
.TP
|
||||
.BI "\-n, \-\-nc-permitted " name
|
||||
Add permitted NameConstraint extension to certificate.
|
||||
Add permitted NameConstraint extension to certificate. For DNS or email
|
||||
constraints, the identity type is not always detectable by the given name. Use
|
||||
the
|
||||
.B dns:
|
||||
or
|
||||
.B email:
|
||||
prefix to force a constraint type.
|
||||
.TP
|
||||
.BI "\-N, \-\-nc-excluded " name
|
||||
Add excluded NameConstraint extension to certificate.
|
||||
Add excluded NameConstraint extension to certificate. For DNS or email
|
||||
constraints, the identity type is not always detectable by the given name. Use
|
||||
the
|
||||
.B dns:
|
||||
or
|
||||
.B email:
|
||||
prefix to force a constraint type.
|
||||
.TP
|
||||
.BI "\-M, \-\-policy-mapping " issuer-oid:subject-oid
|
||||
Add policyMapping from issuer to subject OID.
|
||||
|
||||
@@ -127,10 +127,22 @@ times.
|
||||
Set path length constraint.
|
||||
.TP
|
||||
.BI "\-n, \-\-nc-permitted " name
|
||||
Add permitted NameConstraint extension to certificate.
|
||||
Add permitted NameConstraint extension to certificate. For DNS or email
|
||||
constraints, the identity type is not always detectable by the given name. Use
|
||||
the
|
||||
.B dns:
|
||||
or
|
||||
.B email:
|
||||
prefix to force a constraint type.
|
||||
.TP
|
||||
.BI "\-N, \-\-nc-excluded " name
|
||||
Add excluded NameConstraint extension to certificate.
|
||||
Add excluded NameConstraint extension to certificate. For DNS or email
|
||||
constraints, the identity type is not always detectable by the given name. Use
|
||||
the
|
||||
.B dns:
|
||||
or
|
||||
.B email:
|
||||
prefix to force a constraint type.
|
||||
.TP
|
||||
.BI "\-M, \-\-policy-mapping " issuer-oid:subject-oid
|
||||
Add policyMapping from issuer to subject OID.
|
||||
|
||||
Reference in New Issue
Block a user