--- On Wed, 1/27/10, Mircea Carasel <[email protected]> wrote:
> Scott Lawrence <[email protected]>
> wrote:
> > On Tue, 2010-01-26 at 13:54 -0800, George Niculae
> wrote:
> >> Hi All,
> >>
> >> as a resolution for XX-7320: Allow export of
> Certificate Authority I
> >> am thinking to put links on certificate names
> within CA table - so one
> >> could easily download the file by accessing a
> link.
> >>
> >> Any thoughts on this one?
> >
> > That seems like a good approach in general.
> >
> > Ideally, we would only allow the download of our own
> private CA, since
> > we really have no business being a source for ones
> that belong to
> > someone else, but the potential for added complexity
> is too high, so
> > just make them all links.
>
> There is already a validation in place for certificate
> delete
> operation. Our own private CA cannot be deleted
> Our own private CA is first created inside
> ${sysdir.var}/certdb and
> then copied into authorities directory.
> The validation method prevents deletion of certificates
> found in
> ${sysdir.var}/certdb location:
An alternative to this validation could be to check the issuer of the
certificate using javax.security.cert.X509Certificate.getIssuerDN.
George
_______________________________________________
sipx-dev mailing list [email protected]
List Archive: http://list.sipfoundry.org/archive/sipx-dev
Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-dev
sipXecs IP PBX -- http://www.sipfoundry.org/