Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ExtendedKeyUsage option missing in SFA generated Certificates #928

Open
hussamnasir opened this issue Sep 27, 2018 · 1 comment
Open

ExtendedKeyUsage option missing in SFA generated Certificates #928

hussamnasir opened this issue Sep 27, 2018 · 1 comment

Comments

@hussamnasir
Copy link
Contributor

Looking ahead into the future of SSL certificates used in GENI, we want the Non-CA certificates being generated for GENI to have the EKU bit set to serverAuth,clientAuth,timeStamping,emailProtection,codeSigning . The CA on the Server side has been set to EKU=any

Similar issue addressed in the GENI-CH code GENI-NSF/geni-ch#608

@hussamnasir
Copy link
Contributor Author

Pull request #929 addresses this. The change may have other implication and should be thoroughly investigated before a merge. We aer manually installing this on the Production GENI CH for now

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant