[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [PATCH] Enforce EKU requirements for client tokens during PKINIT
On Mar 14, 2008, at 1:55 PM, Love Hörnquist Åstrand wrote:
>
> Ok, I just added a certificate selection language to heimdal's hx509.
>
> hxtool query \
> --expr='"1.3.6.1.5.2.3.5" IN %{certificate.eku} AND %
> {certificate.subject} TAILMATCH "C=SE"' \
> FILE:$srcdir/data/kdc.crt > /dev/null || exit 1
>
> Would this do ?
How rich is this expression allowed to be?
-- Tim
smime.p7s