pki tool shows and builds crlSign keyUsage
This commit is contained in:
@@ -120,6 +120,10 @@ static int issue()
|
|||||||
{
|
{
|
||||||
flags |= X509_CLIENT_AUTH;
|
flags |= X509_CLIENT_AUTH;
|
||||||
}
|
}
|
||||||
|
else if (streq(arg, "crlSign"))
|
||||||
|
{
|
||||||
|
flags |= X509_CRL_SIGN;
|
||||||
|
}
|
||||||
else if (streq(arg, "ocspSigning"))
|
else if (streq(arg, "ocspSigning"))
|
||||||
{
|
{
|
||||||
flags |= X509_OCSP_SIGNER;
|
flags |= X509_OCSP_SIGNER;
|
||||||
@@ -378,7 +382,7 @@ static void __attribute__ ((constructor))reg()
|
|||||||
{"[--in file] [--type pub|pkcs10] --cakey file | --cakeyid hex",
|
{"[--in file] [--type pub|pkcs10] --cakey file | --cakeyid hex",
|
||||||
" --cacert file --dn subject-dn [--san subjectAltName]+",
|
" --cacert file --dn subject-dn [--san subjectAltName]+",
|
||||||
"[--lifetime days] [--serial hex] [--crl uri]+ [--ocsp uri]+",
|
"[--lifetime days] [--serial hex] [--crl uri]+ [--ocsp uri]+",
|
||||||
"[--ca] [--pathlen len] [--flag serverAuth|clientAuth|ocspSigning]+",
|
"[--ca] [--pathlen len] [--flag serverAuth|clientAuth|crlSign|ocspSigning]+",
|
||||||
"[--digest md5|sha1|sha224|sha256|sha384|sha512] [--outform der|pem]"},
|
"[--digest md5|sha1|sha224|sha256|sha384|sha512] [--outform der|pem]"},
|
||||||
{
|
{
|
||||||
{"help", 'h', 0, "show usage information"},
|
{"help", 'h', 0, "show usage information"},
|
||||||
|
|||||||
@@ -105,6 +105,10 @@ static void print_x509(x509_t *x509)
|
|||||||
{
|
{
|
||||||
printf("CA ");
|
printf("CA ");
|
||||||
}
|
}
|
||||||
|
if (flags & X509_CRL_SIGN)
|
||||||
|
{
|
||||||
|
printf("CRLSign ");
|
||||||
|
}
|
||||||
if (flags & X509_AA)
|
if (flags & X509_AA)
|
||||||
{
|
{
|
||||||
printf("AA ");
|
printf("AA ");
|
||||||
|
|||||||
@@ -113,6 +113,10 @@ static int self()
|
|||||||
{
|
{
|
||||||
flags |= X509_CLIENT_AUTH;
|
flags |= X509_CLIENT_AUTH;
|
||||||
}
|
}
|
||||||
|
else if (streq(arg, "crlSign"))
|
||||||
|
{
|
||||||
|
flags |= X509_CRL_SIGN;
|
||||||
|
}
|
||||||
else if (streq(arg, "ocspSigning"))
|
else if (streq(arg, "ocspSigning"))
|
||||||
{
|
{
|
||||||
flags |= X509_OCSP_SIGNER;
|
flags |= X509_OCSP_SIGNER;
|
||||||
@@ -257,7 +261,7 @@ static void __attribute__ ((constructor))reg()
|
|||||||
{"[--in file | --keyid hex] [--type rsa|ecdsa]",
|
{"[--in file | --keyid hex] [--type rsa|ecdsa]",
|
||||||
" --dn distinguished-name [--san subjectAltName]+",
|
" --dn distinguished-name [--san subjectAltName]+",
|
||||||
"[--lifetime days] [--serial hex] [--ca] [--ocsp uri]+",
|
"[--lifetime days] [--serial hex] [--ca] [--ocsp uri]+",
|
||||||
"[--flag serverAuth|clientAuth|ocspSigning]+",
|
"[--flag serverAuth|clientAuth|crlSign|ocspSigning]+",
|
||||||
"[--digest md5|sha1|sha224|sha256|sha384|sha512] [--outform der|pem]"},
|
"[--digest md5|sha1|sha224|sha256|sha384|sha512] [--outform der|pem]"},
|
||||||
{
|
{
|
||||||
{"help", 'h', 0, "show usage information"},
|
{"help", 'h', 0, "show usage information"},
|
||||||
|
|||||||
Reference in New Issue
Block a user