Skip to content

Feature Request: Support Certificate Type Restrictions #4339

Open
@jmayclin

Description

Problem:

Customers wish to restrict certificates on both the local and peer side of connections. Additionally customers wish to be able to restrict certificate key types. This issue will be used for tracking the implementation of this feature.

Solution:

  • apply certificate_signature_preferences local certs
  • add a certificate_key_preferences field to the security policy
  • add compliance rule for RFC9151 support
  • retrieve the associated digest from rsa-pss signatures to fully support RSA-PSS certs

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions