pki: Print and document the name constraint type for DNS or email constraints

As email constraints may be for a specific host, it is not clear from the
name itself if it is a DNS or email constraint.
This commit is contained in:
Martin Willi
2014-10-30 11:40:48 +01:00
parent a6c8647eca
commit b9d38c9fa2
3 changed files with 46 additions and 6 deletions
+18 -2
View File
@@ -65,6 +65,22 @@ static void print_key(private_key_t *key)
}
}
/**
* Get a prefix for a named constraint identity type
*/
static char* get_type_pfx(identification_t *id)
{
switch (id->get_type(id))
{
case ID_RFC822_ADDR:
return "email:";
case ID_FQDN:
return "dns:";
default:
return "";
}
}
/**
* Print X509 specific certificate information
*/
@@ -202,7 +218,7 @@ static void print_x509(x509_t *x509)
printf("Permitted NameConstraints:\n");
first = FALSE;
}
printf(" %Y\n", id);
printf(" %s%Y\n", get_type_pfx(id), id);
}
enumerator->destroy(enumerator);
first = TRUE;
@@ -214,7 +230,7 @@ static void print_x509(x509_t *x509)
printf("Excluded NameConstraints:\n");
first = FALSE;
}
printf(" %Y\n", id);
printf(" %s%Y\n", get_type_pfx(id), id);
}
enumerator->destroy(enumerator);