projects
/
certmaster.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
fix the version in the makefile :(
[certmaster.git]
/
certmaster
/
certs.py
diff --git
a/certmaster/certs.py
b/certmaster/certs.py
index
8a1db3a
..
b59a972
100644
(file)
--- a/
certmaster/certs.py
+++ b/
certmaster/certs.py
@@
-37,7
+37,7
@@
def make_keypair(dest=None):
return pkey
return pkey
-def make_csr(pkey, dest=None, cn=None):
+def make_csr(pkey, dest=None, cn=None
, hostname=None, emailaddr=None
):
req = crypto.X509Req()
req.get_subject()
subj = req.get_subject()
req = crypto.X509Req()
req.get_subject()
subj = req.get_subject()
@@
-48,9
+48,15
@@
def make_csr(pkey, dest=None, cn=None):
subj.OU = def_ou
if cn:
subj.CN = cn
subj.OU = def_ou
if cn:
subj.CN = cn
+ elif hostname:
+ subj.CN = hostname
else:
else:
- subj.CN = utils.get_hostname()
- subj.emailAddress = 'root@%s' % subj.CN
+ subj.CN = utils.gethostname()
+
+ if emailaddr:
+ subj.emailAddress = emailaddr
+ else:
+ subj.emailAddress = 'root@%s' % subj.CN
req.set_pubkey(pkey)
req.sign(pkey, 'md5')
req.set_pubkey(pkey)
req.sign(pkey, 'md5')
@@
-93,7
+99,11
@@
def create_ca(CN="Certmaster Certificate Authority", ca_key_file=None, ca_cert_f
cacert.set_issuer(careq.get_subject())
cacert.set_subject(careq.get_subject())
cacert.set_pubkey(careq.get_pubkey())
cacert.set_issuer(careq.get_subject())
cacert.set_subject(careq.get_subject())
cacert.set_pubkey(careq.get_pubkey())
- cacert.sign(cakey, 'md5')
+ cacert.set_version(2)
+ xt = crypto.X509Extension('basicConstraints',1,'CA:TRUE')
+ # FIXME - add subjectkeyidentifier and authoritykeyidentifier extensions, too)
+ cacert.add_extensions((xt,))
+ cacert.sign(cakey, 'sha1')
if ca_cert_file:
destfo = open(ca_cert_file, 'w')
destfo.write(crypto.dump_certificate(crypto.FILETYPE_PEM, cacert))
if ca_cert_file:
destfo = open(ca_cert_file, 'w')
destfo.write(crypto.dump_certificate(crypto.FILETYPE_PEM, cacert))
@@
-131,7
+141,11
@@
def create_slave_certificate(csr, cakey, cacert, cadir, slave_cert_file=None):
cert.set_issuer(cacert.get_subject())
cert.set_subject(csr.get_subject())
cert.set_pubkey(csr.get_pubkey())
cert.set_issuer(cacert.get_subject())
cert.set_subject(csr.get_subject())
cert.set_pubkey(csr.get_pubkey())
- cert.sign(cakey, 'md5')
+ cert.set_version(2)
+ xt = crypto.X509Extension('basicConstraints', False ,'CA:FALSE')
+ # FIXME - add subjectkeyidentifier and authoritykeyidentifier extensions, too)
+ cert.add_extensions((xt,))
+ cert.sign(cakey, 'sha1')
if slave_cert_file:
destfo = open(slave_cert_file, 'w')
destfo.write(crypto.dump_certificate(crypto.FILETYPE_PEM, cert))
if slave_cert_file:
destfo = open(slave_cert_file, 'w')
destfo.write(crypto.dump_certificate(crypto.FILETYPE_PEM, cert))