PKINIT certificate creation with GnuTLS' certtool

2016-01-08 Thread Rick van Rein
Hello, I have reported a feature request with GnuTLS, suggesting it to support PKINIT certificate generation with certtool, https://gitlab.com/gnutls/gnutls/issues/62 Nikos Mavrogiannopoulos is graciously helping out, and has created a proposed commit, https://gitlab.com/gnutls/gnutls/commits/krb

Re: PKINIT certificate creation with GnuTLS' certtool

2016-01-08 Thread Greg Hudson
On 01/08/2016 06:59 PM, Rick van Rein wrote: > kdc_principal_seq mentions name_type==1, or NT-PRINCIPAL. Should > this not be NT-SRV-INST [Section 6.2 of RFC4120] or does PKINIT not > care in practice? (The spec does not, but how about implementations?) I don't think any implementation