Seth Schoen
|
900120de95
|
move docstring to the right place
|
2012-10-18 17:20:59 -07:00 |
|
Seth Schoen
|
24f4e065e5
|
lowercase names and remove duplicates
|
2012-08-12 18:49:26 -07:00 |
|
Seth Schoen
|
8b082f9fde
|
evidently, current best practice is to include ALL DNS names, including the primary name, as SANs
|
2012-08-10 16:26:25 -07:00 |
|
Seth Schoen
|
06357addf0
|
min_key_size → min_keysize
|
2012-07-19 23:22:52 -07:00 |
|
Seth Schoen
|
90f4b4daeb
|
move configuratoin parameters into config file; add extra sanity checks
|
2012-07-19 23:19:39 -07:00 |
|
Seth Schoen
|
e857154682
|
updated modulus blacklisting stuff
|
2012-07-17 00:33:45 -07:00 |
|
Seth Schoen
|
ac0defac00
|
remove client-side dependency on CSR.py
|
2012-07-16 15:11:10 -07:00 |
|
Seth Schoen
|
e70424dd4a
|
database-backed blacklisting of moduli and names
|
2012-07-16 15:02:07 -07:00 |
|
Seth Schoen
|
88c5b270ef
|
implement locking for issuing certs with openssl ca
|
2012-07-14 23:01:39 -07:00 |
|
Seth Schoen
|
be58b8759a
|
notes on locking and concurrency
|
2012-07-14 14:56:19 -07:00 |
|
Seth Schoen
|
3b624c40a7
|
remove debug print
|
2012-07-13 22:58:00 -07:00 |
|
Seth Schoen
|
32c2ba8e71
|
correctly emit subject alternative names and remove most user-supplied data from cert
|
2012-07-13 22:50:58 -07:00 |
|
Seth Schoen
|
34e3663399
|
passing type unicode instead of str to M2Crypto causes failures (!)
|
2012-07-13 19:30:58 -07:00 |
|
Seth Schoen
|
5b43540452
|
crazy M2Crypto bug: you have to get_pubkey().get_rsa() not just get_pubkey()
|
2012-07-13 19:29:36 -07:00 |
|
Seth Schoen
|
764b2783a7
|
explicitly require m3crypto inside ../m3/lib/python
|
2012-07-13 14:49:34 -07:00 |
|
Eric Wustrow
|
956ea28b95
|
use M2Crypto in CSR verify/sign/encrypt
|
2012-07-12 20:30:46 -04:00 |
|
Eric Wustrow
|
9ccd7d2e1e
|
use M2Crypto (patched to support X509.Request.get_extensions) to read the SANs from the CSR; remove pkcs10.py
|
2012-07-12 19:38:37 -04:00 |
|
Eric Wustrow
|
1c129ea1d7
|
use M2Crypto for parse function
|
2012-07-12 19:10:54 -04:00 |
|
Eric Wustrow
|
19df04c516
|
use M2Crypto instead of openssl command line/subprocess for CSR parsing
|
2012-07-12 18:07:13 -04:00 |
|
Eric Wustrow
|
42999f7bb9
|
use M2Crypto for getting public key length
|
2012-07-12 14:55:00 -04:00 |
|
Seth Schoen
|
ac3441a972
|
changes to make CSR.issue() successfully issue certs
|
2012-07-09 00:01:19 -07:00 |
|
Seth Schoen
|
bd578f9796
|
moving everything server-side to server-ca directory
|
2012-07-06 14:45:26 -07:00 |
|