Files
freeipa/ipatests
Fraser Tweedale dfbdb53238 cert-request: match names against principal aliases
Currently we do not check Kerberos principal aliases when validating
a CSR.  Enhance cert-request to accept the following scenarios:

- for hosts and services: CN and SAN dnsNames match a principal
  alias (realm and service name must be same as nominated principal)

- for all principal types: UPN or KRB5PrincipalName othername match
  any principal alias.

Fixes: https://fedorahosted.org/freeipa/ticket/6295
Reviewed-By: Martin Babinsky <mbabinsk@redhat.com>
Reviewed-By: Milan Kubik <mkubik@redhat.com>
2016-12-06 16:13:45 +01:00
..
2016-11-14 18:08:15 +01:00
2013-06-17 19:22:50 +02:00
2015-10-22 18:34:46 +02:00
2014-11-21 12:14:44 +01:00
2015-09-01 11:42:01 +02:00
2015-09-01 11:42:01 +02:00
2016-10-20 18:43:37 +02:00
2016-11-30 13:32:30 +01:00
2016-12-02 15:05:33 +01:00