Re: rpki-client: check inherit constraint on TAs earlier on

2022-09-03 Thread Theo Buehler
On Sat, Sep 03, 2022 at 01:08:35PM +, Job Snijders wrote: > RPKI Trust Anchors (self-signed root certificates) MAY NOT contain > 'inherit' elements in their RFC 3779 resource extensions according to > RFC 6490 section 2.2. > > We could check way earlier on in the validation process whether

rpki-client: check inherit constraint on TAs earlier on

2022-09-03 Thread Job Snijders
RPKI Trust Anchors (self-signed root certificates) MAY NOT contain 'inherit' elements in their RFC 3779 resource extensions according to RFC 6490 section 2.2. We could check way earlier on in the validation process whether the TA certificate conforms to this constraint. The below changeset moves