Skip to content

CSR/CA/X509 refactor and extension support - #285

Draft
aidankeefe2022 wants to merge 1 commit into
wolfSSL:mainfrom
aidankeefe2022:csr-ca-x509-only
Draft

CSR/CA/X509 refactor and extension support#285
aidankeefe2022 wants to merge 1 commit into
wolfSSL:mainfrom
aidankeefe2022:csr-ca-x509-only

Conversation

@aidankeefe2022

Copy link
Copy Markdown
Member

Rework the req, x509 and ca commands and their extension handling, and extend the x509 request test suite to cover them.

  • req: rework option parsing and the CSR/self-sign/CA-sign paths, add -serial and -CAkey
  • config: parse subjectAltName, authorityKeyIdentifier, subjectKeyIdentifier, keyUsage, extendedKeyUsage and basicConstraints, from both -addext and config sections

-addext remains single-use, as on main.

fixed issues from skoll review

scope reduction

Rework the req, x509 and ca commands and their extension handling, and
extend the x509 request test suite to cover them.

  - req: rework option parsing and the CSR/self-sign/CA-sign paths, add
    -serial and -CAkey
  - config: parse subjectAltName, authorityKeyIdentifier,
    subjectKeyIdentifier, keyUsage, extendedKeyUsage and
    basicConstraints, from both -addext and config sections

wolfCLU_GetOpt is rewritten as a left-to-right argv walk rather than a
scan of the option table, which the reworked x509 parsing depends on.
That is cross-cutting, so the commands taking positional arguments
(enc, dsaparam, dhparam, genkey, rand, sign/verify) are adapted to it
and wolfCLU_checkForArg now takes a struct option. Commands that only
take flags are untouched.

-addext remains single-use, as on main.

fixed issues from skoll review

scope reduction
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant