diff options
| author | Kenny Root <kroot@google.com> | 2012-08-07 11:36:02 -0700 |
|---|---|---|
| committer | Brian Carlstrom <bdc@google.com> | 2012-08-08 15:54:02 -0700 |
| commit | 83a7cea6ad5c5f066e55aeddd6da27d3ef5e62c1 (patch) | |
| tree | 3c33956b11c9e9e02246b1c9152d288f635086e4 /annotations/generate_annotated_java_files.py | |
| parent | 678205c9e0a4ad9fe1dbb4f30eefc797c08000e0 (diff) | |
Add chain building to TrustedCertificateStore
Since TrustedCertificateStore has information needed, use it to build
certificate chains.
OpenSSL uses Authority Key Identifier in extensions to determine if the
certificate is the same as itself. There are problems with key rotation
when a different certificate serial signs a key with the same subject
identifier. It appears to be the same with the old code, but it may
generate an invalid chain.
(cherry-picked from 3fb088d79e446063ef743362a030e1cfb80b2178)
Change-Id: I8149bed1a0ae537f75da5dc3f3d7e3ccab353f91
Diffstat (limited to 'annotations/generate_annotated_java_files.py')
0 files changed, 0 insertions, 0 deletions
