aboutsummaryrefslogtreecommitdiff
path: root/openssl/README
diff options
context:
space:
mode:
Diffstat (limited to 'openssl/README')
-rw-r--r--openssl/README8
1 files changed, 8 insertions, 0 deletions
diff --git a/openssl/README b/openssl/README
index 4d71867c..1bcf9546 100644
--- a/openssl/README
+++ b/openssl/README
@@ -227,6 +227,14 @@ Random reminders and notes to myself:
- May need to check AKID in crypto/x509/x509_vfy.c:get_crl().
+- "Resource sets" -- represent internally as extensions, inheritance
+ disallowed. Need I/O functions. Groveling doc/openssl.txt, I see
+ X509V3_EXT_conf_nid(), X509V3_EXT_print_fp(), and X509V3_EXT_d2i()
+ as the functions most likely to be useful. Sections 2 & 3 of that
+ file are generally informative on how to do this, difficulty is just
+ that most of it, unsurprisingly, is geared towards extensions in
+ certificates and CRLs, not bare extensions. But should suffice.
+
The June meeting at APNIC came up with a list of desired OpenSSL