View Issue Details

IDProjectCategoryView StatusLast Update
000741110000-012: DiscoverySpecpublic2022-06-21 09:12
ReporterMatthias Damm Assigned ToRandy Armstrong  
PrioritynormalSeverityminorReproducibilityhave not tried
Status closedResolutionfixed 
Product Version1.04 
Target Version1.05Fixed in Version1.05.02 RC1 
Summary0007411: Relation of CSR extendedKeyUsage and ApplicationType in StartSigningRequest
Description

The referenced application in StartSigningRequest (applicationId) has an ApplicationType.
See also related Mantis issue 0007410

The CSR may contain an „extendedKeyUsage“ with „serverAuth, clientAuth“.
We expected that the extendedKeyUsage is derived from the ApplicationType.

What happens if the requested extendedKeyUsage is different than the ApplicationType?
Is the extendedKeyUsage required in the CSR?

Part 12 StartSigningRequest is silent on this.

TagsNo tags attached.
Commit Version
Fix Due Date

Relationships

related to 0007410 closedRandy Armstrong 10000-006: Mappings Requirements for setting ApplicationType CLIENTANDSERVER 

Activities

Randy Armstrong

2022-06-20 11:05

administrator   ~0016857

Any bits set in basicConstraints or extendedKeyUsage fields in the CSR are ignored by the CertificateManager. The CertificateManager uses values that are appropriate and complaint with the specification.

Jim Luth

2022-06-21 09:12

administrator   ~0016930

Agreed to changes edited in Munich F2F.

Issue History

Date Modified Username Field Change
2021-11-12 10:06 Matthias Damm New Issue
2021-11-12 10:06 Matthias Damm Relationship added related to 0007410
2021-11-16 17:51 Jim Luth Assigned To => Randy Armstrong
2021-11-16 17:51 Jim Luth Status new => assigned
2022-06-20 11:05 Randy Armstrong Status assigned => resolved
2022-06-20 11:05 Randy Armstrong Resolution open => fixed
2022-06-20 11:05 Randy Armstrong Note Added: 0016857
2022-06-21 09:12 Jim Luth Status resolved => closed
2022-06-21 09:12 Jim Luth Fixed in Version => 1.05.02 RC1
2022-06-21 09:12 Jim Luth Note Added: 0016930