Add Subject Alternate Name extension
This commit is contained in:
parent
b46574b635
commit
f4168b1161
|
|
@ -5,6 +5,7 @@ use nid::Nid;
|
||||||
pub enum ExtensionType {
|
pub enum ExtensionType {
|
||||||
KeyUsage,
|
KeyUsage,
|
||||||
ExtKeyUsage,
|
ExtKeyUsage,
|
||||||
|
SubjectAltName,
|
||||||
OtherNid(Nid),
|
OtherNid(Nid),
|
||||||
OtherStr(String),
|
OtherStr(String),
|
||||||
}
|
}
|
||||||
|
|
@ -13,6 +14,7 @@ pub enum ExtensionType {
|
||||||
pub enum Extension {
|
pub enum Extension {
|
||||||
KeyUsage(Vec<KeyUsageOption>),
|
KeyUsage(Vec<KeyUsageOption>),
|
||||||
ExtKeyUsage(Vec<ExtKeyUsageOption>),
|
ExtKeyUsage(Vec<ExtKeyUsageOption>),
|
||||||
|
SubjectAltName(Vec<(AltNameOption,String)>),
|
||||||
OtherNid(Nid,String),
|
OtherNid(Nid,String),
|
||||||
OtherStr(String,String),
|
OtherStr(String,String),
|
||||||
}
|
}
|
||||||
|
|
@ -22,6 +24,7 @@ impl Extension {
|
||||||
match self {
|
match self {
|
||||||
&Extension::KeyUsage(_) => ExtensionType::KeyUsage,
|
&Extension::KeyUsage(_) => ExtensionType::KeyUsage,
|
||||||
&Extension::ExtKeyUsage(_) => ExtensionType::ExtKeyUsage,
|
&Extension::ExtKeyUsage(_) => ExtensionType::ExtKeyUsage,
|
||||||
|
&Extension::SubjectAltName(_) => ExtensionType::SubjectAltName,
|
||||||
&Extension::OtherNid(nid,_) => ExtensionType::OtherNid(nid),
|
&Extension::OtherNid(nid,_) => ExtensionType::OtherNid(nid),
|
||||||
&Extension::OtherStr(ref s,_) => ExtensionType::OtherStr(s.clone()),
|
&Extension::OtherStr(ref s,_) => ExtensionType::OtherStr(s.clone()),
|
||||||
}
|
}
|
||||||
|
|
@ -33,6 +36,7 @@ impl ExtensionType {
|
||||||
match self {
|
match self {
|
||||||
&ExtensionType::KeyUsage => Some(Nid::KeyUsage),
|
&ExtensionType::KeyUsage => Some(Nid::KeyUsage),
|
||||||
&ExtensionType::ExtKeyUsage => Some(Nid::ExtendedKeyUsage),
|
&ExtensionType::ExtKeyUsage => Some(Nid::ExtendedKeyUsage),
|
||||||
|
&ExtensionType::SubjectAltName => Some(Nid::SubjectAltName),
|
||||||
&ExtensionType::OtherNid(nid) => Some(nid),
|
&ExtensionType::OtherNid(nid) => Some(nid),
|
||||||
&ExtensionType::OtherStr(_) => None,
|
&ExtensionType::OtherStr(_) => None,
|
||||||
}
|
}
|
||||||
|
|
@ -61,6 +65,7 @@ impl ToString for Extension {
|
||||||
match self {
|
match self {
|
||||||
&Extension::KeyUsage(ref purposes) => join(purposes.iter(),","),
|
&Extension::KeyUsage(ref purposes) => join(purposes.iter(),","),
|
||||||
&Extension::ExtKeyUsage(ref purposes) => join(purposes.iter(),","),
|
&Extension::ExtKeyUsage(ref purposes) => join(purposes.iter(),","),
|
||||||
|
&Extension::SubjectAltName(ref names) => join(names.iter().map(|&(ref opt,ref val)|opt.to_string()+":"+&val),","),
|
||||||
&Extension::OtherNid(_,ref value) => value.clone(),
|
&Extension::OtherNid(_,ref value) => value.clone(),
|
||||||
&Extension::OtherStr(_,ref value) => value.clone(),
|
&Extension::OtherStr(_,ref value) => value.clone(),
|
||||||
}
|
}
|
||||||
|
|
@ -131,3 +136,30 @@ impl fmt::Display for ExtKeyUsageOption {
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[derive(Clone, Copy)]
|
||||||
|
pub enum AltNameOption {
|
||||||
|
Other,
|
||||||
|
Email,
|
||||||
|
DNS,
|
||||||
|
//X400, // Not supported by OpenSSL
|
||||||
|
Directory,
|
||||||
|
//EDIParty, // Not supported by OpenSSL
|
||||||
|
URI,
|
||||||
|
IPAddress,
|
||||||
|
RegisteredID,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl fmt::Display for AltNameOption {
|
||||||
|
fn fmt(&self, f: &mut fmt::Formatter) -> Result<(), fmt::Error> {
|
||||||
|
f.pad(match self {
|
||||||
|
&AltNameOption::Other => "otherName",
|
||||||
|
&AltNameOption::Email => "email",
|
||||||
|
&AltNameOption::DNS => "DNS",
|
||||||
|
&AltNameOption::Directory => "dirName",
|
||||||
|
&AltNameOption::URI => "URI",
|
||||||
|
&AltNameOption::IPAddress => "IP",
|
||||||
|
&AltNameOption::RegisteredID => "RID",
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
|
||||||
|
|
@ -5,7 +5,8 @@ use std::fs::File;
|
||||||
|
|
||||||
use crypto::hash::Type::{SHA256};
|
use crypto::hash::Type::{SHA256};
|
||||||
use x509::{X509, X509Generator};
|
use x509::{X509, X509Generator};
|
||||||
use x509::extension::Extension::{KeyUsage,ExtKeyUsage,OtherNid,OtherStr};
|
use x509::extension::Extension::{KeyUsage,ExtKeyUsage,SubjectAltName,OtherNid,OtherStr};
|
||||||
|
use x509::extension::AltNameOption as SAN;
|
||||||
use x509::extension::KeyUsageOption::{DigitalSignature, KeyEncipherment};
|
use x509::extension::KeyUsageOption::{DigitalSignature, KeyEncipherment};
|
||||||
use x509::extension::ExtKeyUsageOption::{self, ClientAuth, ServerAuth};
|
use x509::extension::ExtKeyUsageOption::{self, ClientAuth, ServerAuth};
|
||||||
use nid::Nid;
|
use nid::Nid;
|
||||||
|
|
@ -19,6 +20,7 @@ fn test_cert_gen() {
|
||||||
.set_sign_hash(SHA256)
|
.set_sign_hash(SHA256)
|
||||||
.add_extension(KeyUsage(vec![DigitalSignature, KeyEncipherment]))
|
.add_extension(KeyUsage(vec![DigitalSignature, KeyEncipherment]))
|
||||||
.add_extension(ExtKeyUsage(vec![ClientAuth, ServerAuth, ExtKeyUsageOption::Other("2.999.1".to_owned())]))
|
.add_extension(ExtKeyUsage(vec![ClientAuth, ServerAuth, ExtKeyUsageOption::Other("2.999.1".to_owned())]))
|
||||||
|
.add_extension(SubjectAltName(vec![(SAN::DNS,"example.com".to_owned())]))
|
||||||
.add_extension(OtherNid(Nid::BasicConstraints,"critical,CA:TRUE".to_owned()))
|
.add_extension(OtherNid(Nid::BasicConstraints,"critical,CA:TRUE".to_owned()))
|
||||||
.add_extension(OtherStr("2.999.2".to_owned(),"ASN1:UTF8:example value".to_owned()));
|
.add_extension(OtherStr("2.999.2".to_owned(),"ASN1:UTF8:example value".to_owned()));
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue