4 ms·
This looks great! I wanted to bundle a chain of certs, check that the leaf was <some domain> and its key signed <some data>, and that the bundle provided a pat
by RustyRussell 3y ago
This looks great!
I wanted to bundle a chain of certs, check that the leaf was <some domain> and its key signed <some data>, and that the bundle provided a path to a locally-trusted root. This allows third-party serving of signed data, rather than having to trade your IP address for validation.
Doing so with existing tools was so terrible that I was pretty sure my result was grossly insecure :(
I look forward to the promised lower-level APIs!