Browse Source

add policy open_usage

This policy will be used for certificate with various keyUsage
parameters. Etcd for example.

Change-Id: I2a6387f8b7ee58fb6f256881e3e09142f13119a9
pull/35/head
Tomáš Kukrál 7 years ago
parent
commit
a480e1663c
1 changed files with 2 additions and 0 deletions
  1. +2
    -0
      salt/files/_pki.conf

+ 2
- 0
salt/files/_pki.conf View File

{%- elif signing_policy.type == 'v3_edge_ca' %} {%- elif signing_policy.type == 'v3_edge_ca' %}
- basicConstraints: "CA:TRUE,pathlen:0" - basicConstraints: "CA:TRUE,pathlen:0"
- keyUsage: "critical cRLSign,keyCertSign" - keyUsage: "critical cRLSign,keyCertSign"
{%- elif signing_policy.type == 'v3_edge_cert_open' %}
- basicConstraints: "CA:FALSE"
{%- endif %} {%- endif %}
- subjectKeyIdentifier: hash - subjectKeyIdentifier: hash
- authorityKeyIdentifier: keyid,issuer:always - authorityKeyIdentifier: keyid,issuer:always

Loading…
Cancel
Save