[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH] Enforce EKU requirements for client tokens during PKINIT



On Mar 14, 2008, at 1:55 PM, Love Hörnquist Åstrand wrote:
>
> Ok, I just added a certificate selection language to heimdal's hx509.
>
> hxtool query \
> 	--expr='"1.3.6.1.5.2.3.5" IN %{certificate.eku} AND % 
> {certificate.subject} TAILMATCH "C=SE"'  \
> 	FILE:$srcdir/data/kdc.crt > /dev/null || exit 1
>
> Would this do ?

How rich is this expression allowed to be?

-- Tim

smime.p7s