Skip to content

Generated X.509 certs should be RFC 5280 compliant by default #13603

@DDvO

Description

@DDvO

Meanwhile we have stronger checks for X.509 certificates to comply to RFC 5280,
at least when strict checking is enabled (e.g., using -x509_strict).

Yet unfortunately the OpenSSL apps by default tend to generate certs that are not compliant.
In particular, X.509v3 certs (i.e., those having any X.509 extensions) MUST include

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions