[19535] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: NSS PKINIT requires nsCertType extension?

daemon@ATHENA.MIT.EDU (Matt Rogers)
Wed Feb 1 11:44:49 2017

MIME-Version: 1.0
In-Reply-To: <9ab9b404-3429-5ba6-4dd0-6d1fe04cf7d2@mit.edu>
From: Matt Rogers <mrogers@redhat.com>
Date: Wed, 1 Feb 2017 11:44:10 -0500
Message-ID: <CAAeFVfy3w7P=s6DvKapdQY2xJeyjAc=Hk6B8nLax+oykT2LW1Q@mail.gmail.com>
To: Greg Hudson <ghudson@mit.edu>
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On Wed, Feb 1, 2017 at 11:07 AM, Greg Hudson <ghudson@mit.edu> wrote:
> On 01/31/2017 10:09 AM, Matt Rogers wrote:
>> It turns out NSS is expecting the Netscape
>> certificate type extension (nsCertType = client/server in
>> openssl.cnf), and adding it to the test certificates made the tests
>> pass. Is this expected, or documented anywhere?
>
> I remember NSS having some behavior differences which made NSS PKINIT
> not a drop-in for the OpenSSL implementation, but I don't remember if
> this was one Nalin had discussed.  I went back and looked at the
> conversation on krbdev in September and October 2011 when we merged it,
> but there wasn't any discussion of behavior differences there.
>
> I've actually been meaning to ask if we can remove the NSS PKINIT
> implementation, since it was motivated by
> https://fedoraproject.org/wiki/FedoraCryptoConsolidation
> which is now defunct.  What led you to try it out?

If it was only used by the crypto consolidation effort then perhaps we
can remove it (I will ask around). The cert authorization plugin
framework needed new functions in the PKINIT crypto backend, which I
wrote for the OpenSSL variant, so I was giving it a shot before I went
about writing NSS versions. But I can hold off on those for now if the
NSS support is in limbo.
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post