ndehadrai / freeipa

Forked from freeipa 5 years ago
Clone

3c354e7 Verify external CA's basic constraint pathlen

Authored and Committed by cheimes 5 years ago
    Verify external CA's basic constraint pathlen
    
    IPA no verifies that intermediate certs of external CAs have a basic
    constraint path len of at least 1 and increasing.
    
    Fixes: https://pagure.io/freeipa/issue/7877
    Signed-off-by: Christian Heimes <cheimes@redhat.com>
    Reviewed-By: Fraser Tweedale <ftweedal@redhat.com>
    Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com>
    
        
file modified
+13 -1