]> git.ipfire.org Git - thirdparty/strongswan.git/commit
pki: Don't generate negative random serial numbers in X.509 certificates
authorMartin Willi <martin@revosec.ch>
Wed, 5 Feb 2014 10:05:28 +0000 (11:05 +0100)
committerMartin Willi <martin@revosec.ch>
Mon, 31 Mar 2014 09:14:58 +0000 (11:14 +0200)
commite49197f15eef80f5559fcb631d4a4c51ae7867e7
tree286b1fac9922c60d2ade3f719f7672fed7caca2a
parent0226ca886deb82e2cecd72706bedbf471911fec1
pki: Don't generate negative random serial numbers in X.509 certificates

According to RFC 5280 4.1.2.2 we MUST force non-negative serial numbers.
src/pki/commands/issue.c
src/pki/commands/self.c