easy-tls
easy-tls copied to clipboard
Ideas for metadata field: OPT
#32
So far:
notAfterdate - Could be done by appending to creation date.- ~An RPC function~ ;-) - This was a joke ..
- Client certificate fingerprint
- ~Random padding~ - Done another way.
- ~Server-Name~ - This would allow the Server-Name to be added to inline-file metadata I could append Server-Name to CA serial number field.
- Fixed Client IP
- Something else ?
Server admins will need to know to which Server can this key connect, so adding Server CommonName to the metadata is going to be vital. However, this does not need to use OPT.
How about my signature $gpg-public-key:tincantech ?
How about a bit field, to specify over-riding server requirements.
0000- User0001- Ignore hwaddr0010- Ignore Custom-Group0100- Ignore expiry- etc..
I have a valid use for this field:
- Lock to the specified X509 certificate .. or not.
Although, even this can be done by appending a lock to the X509 serial number field.
This may be required to mark a key as a group key, not an individual key.