Bugzilla (bugzilla.redhat.com) will be under maintenance for infrastructure upgrades and will not be unavailable on July 31st between 12:30 AM - 05:30 AM UTC. We appreciate your understanding and patience. You can follow status.redhat.com for details.
Bug 1415596 - [RFE] Allow certutil basic constraints to be specified on the command line
Summary: [RFE] Allow certutil basic constraints to be specified on the command line
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: nss
Version: 7.2
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: rc
: ---
Assignee: nss-nspr-maint
QA Contact: BaseOS QE Security Team
URL:
Whiteboard:
Depends On:
Blocks: 1420851
TreeView+ depends on / blocked
 
Reported: 2017-01-23 08:28 UTC by Roman Bobek
Modified: 2020-09-10 10:08 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Enhancement
Doc Text:
Clone Of:
Environment:
Last Closed: 2017-07-31 14:36:19 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Mozilla Foundation 671088 0 -- NEW Allow certutil basic constraints to be specified on the command line 2020-04-27 18:41:01 UTC

Description Roman Bobek 2017-01-23 08:28:33 UTC
Description of problem:
When writing tests, the customer has to pipe in a series of nearly indecipherable numbers to certutil's stdin to create a cert with a basic constraints extension (see tests/chains/chains.sh).

The proposal is to add the following parameters:

    --ca                    : sets the CA constraint to true
    --pathLenConstraint <x> : sets the path length constraint
    --invalid               : do not prohibit the creation of
                              a syntactically-valid but
                              semantically-invalid certificate.

The --invalid flag would be used to allow the creation of invalid certificates in order to test NSS's handling of such invalid certificates.


How reproducible:
Always


Additional info:
There was an upstream BZ opened for this request, but the functionality was not implemented:
https://bugzilla.mozilla.org/show_bug.cgi?id=671088


Note You need to log in before you can comment on or make changes to this bug.