cryptography
cryptography copied to clipboard
FR: Allow clients to set extension policies for x.509 verification
Given that the default policy seems to generally be to verify against the CA/B ruleset (a reasonable default), it would be nice for non-internet PKI users if we could pass our own extension policy rules into the verifier.