smimesign icon indicating copy to clipboard operation
smimesign copied to clipboard

smimesign --list-keys must display only valid certificates for digitalSignature

Open jycr opened this issue 2 years ago • 0 comments

When invoke smimesign --list-keys, it display all certificates including :

  • expired certificates
  • revoked certificates
  • certificates without digitalSignature key usage (cf. https://www.rfc-editor.org/rfc/rfc5280#section-4.2.1.3)

Expired/revoked certificates, and certificates without digitalSignature key usage must not be displayed.

jycr avatar Dec 11 '22 14:12 jycr