3 ms·
There is a Name Constraints extension in X.509[1] that does exactly that, but to my knowledge no browser implements it. [1] https://tools.ietf.org/html/rfc5280
by y0ghur7_xxx 7y ago
There is a Name Constraints extension in X.509[1] that does exactly that, but to my knowledge no browser implements it.
[1] https://tools.ietf.org/html/rfc5280#section-4.2.1.10 https://tools.ietf.org/html/rfc5280#section-4.2.1.10
- markovbot 7y agoand that would have to be baked into the CA certificate, not specified when the CA is trusted. I dont want my browser to ask the CA what it's allowed to do, i want to tell it what it's allowed to do
- y0ghur7_xxx 7y agoIt has to be baked into the CA, so that a browser vendor can check it before inclusion. If the CA specifies domains it is not allowed to sign certificates for, it will not be included.
- jack12 7y ago> but to my knowledge no browser implements it Firefox does, though I don't know how much they check beyond just the dNSName constraints. Here's the unit test making sure it stays working: https://github.com/mozilla/gecko-dev/blob/b8157dfaafc42deb3b9824ab6aab1c3e11636d76/security/manager/ssl/tests/unit/test_name_constraints.js https://github.com/mozilla/gecko-dev/blob/b8157dfaafc42deb3b...