Re: [Freeipa-devel] [PATCH] 0038 cert-request: remove allowed extensions check

2015-08-13 Thread Jan Cholasta
Hi, On 13.8.2015 07:54, Fraser Tweedale wrote: The attached patch fixes https://fedorahosted.org/freeipa/ticket/5205 Simo wrote this some time ago in a (private) discussion about CSR extensions: On 23.1.2014 18:58, Simo Sorce wrote: Regardless of which tool we use, I really think we need

Re: [Freeipa-devel] [PATCH] 0038 cert-request: remove allowed extensions check

2015-08-13 Thread Ade Lee
Fraser, Continuing the discussion started previously, the question is whether IPA should check for the presence of certain extensions. There seem to be two kinds of problems which could be encountered here: 1. User could include a CSR which includes an extension that is not valid for the