Skip to content

Add lint for checking presence of the KeyUsage extension in TLS Subscriber certificates - #1082

Open
defacto64 wants to merge 2 commits into
zmap:masterfrom
defacto64:missing_key_usage
Open

Add lint for checking presence of the KeyUsage extension in TLS Subscriber certificates#1082
defacto64 wants to merge 2 commits into
zmap:masterfrom
defacto64:missing_key_usage

Conversation

@defacto64

Copy link
Copy Markdown
Contributor

Thanks to a recent investigation made by Wayne and shared on the dev-security-policy@mozilla.org mailing list, I discovered that ZLint lacks a check for the KeyUsage extension that - according to the CABF TLS BRs, section 7.1.2.7.11 - SHOULD be present in Subscriber certificates. I therefore put together this trivial lint to fill the gap.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant