Skip to content

Stapled signature checks should support EKU constraints #63

@JeremyRand

Description

@JeremyRand

Normally, EKU constraints can be set on an X.509 cert that's part of the cert chain in the TLS handshake, but this isn't sufficient if the entity in charge of the EKU constraints is a smart contract (since X.509 certs only have a standard keypair controlling them). Setting the EKU constraints as part of the stapled signature check would avoid this problem.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions