Clarify documentation of mbedtls_x509_crt_profile
This commit fixes #1992: The documentation of mbedtls_x509_crt_profile previously stated that the bitfield `allowed_pks` defined which signature algorithms shall be allowed in CRT chains. In actual fact, however, the field also applies to guard the public key of the end entity certificate. This commit changes the documentation to state that `allowed_pks` applies to the public keys of all CRTs in the provided chain. Signed-off-by: Manuel Pégourié-Gonnard <manuel.pegourie-gonnard@arm.com>
This commit is contained in:
parent
a2da9c7e45
commit
2b9fb88281
1 changed files with 3 additions and 1 deletions
|
@ -190,7 +190,9 @@ mbedtls_x509_subject_alternative_name;
|
|||
typedef struct mbedtls_x509_crt_profile
|
||||
{
|
||||
uint32_t allowed_mds; /**< MDs for signatures */
|
||||
uint32_t allowed_pks; /**< PK algs for signatures */
|
||||
uint32_t allowed_pks; /**< PK algs for public keys;
|
||||
* this applies to any CRT
|
||||
* in the provided chain. */
|
||||
uint32_t allowed_curves; /**< Elliptic curves for ECDSA */
|
||||
uint32_t rsa_min_bitlen; /**< Minimum size for RSA keys */
|
||||
}
|
||||
|
|
Loading…
Reference in a new issue