note 41962 deleted from function.openssl-x509-checkpurpose by nlopess
| From: | nlopess@php.net | Date: | Wed, 28 Apr 2004 16:00:50 +0000 |
| Subject: | note 41962 deleted from function.openssl-x509-checkpurpose by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-68962@lists.php.net to get a copy of this message | ||
Note Submitter: seansd@yahoo.com
----
hopefully, this will help anyone else working with this function. output from var_dump of the
purposes of a cert gives:
array(8) {
[1]=>
array(3) {
[0]=>
bool(true)
[1]=>
bool(false)
[2]=>
string(9) "sslclient"
}
[2]=>
array(3) {
[0]=>
bool(false)
[1]=>
bool(false)
[2]=>
string(9) "sslserver"
}
[3]=>
array(3) {
[0]=>
bool(false)
[1]=>
bool(false)
[2]=>
string(11) "nssslserver"
}
[4]=>
array(3) {
[0]=>
bool(true)
[1]=>
bool(false)
[2]=>
string(9) "smimesign"
}
[5]=>
array(3) {
[0]=>
bool(false)
[1]=>
bool(false)
[2]=>
string(12) "smimeencrypt"
}
[6]=>
array(3) {
[0]=>
bool(false)
[1]=>
bool(false)
[2]=>
string(7) "crlsign"
}
[7]=>
array(3) {
[0]=>
bool(true)
[1]=>
bool(true)
[2]=>
string(3) "any"
}
[8]=>
array(3) {
[0]=>
bool(true)
[1]=>
bool(false)
[2]=>
string(10) "ocsphelper"
}
}
the true-false,false-false, etc was confusing until i ran openssl x509 -purpose agains the cert for
more info:
Certificate purposes:
SSL client : Yes
SSL client CA : No
SSL server : No
SSL server CA : No
Netscape SSL server : No
Netscape SSL server CA : No
S/MIME signing : Yes
S/MIME signing CA : No
S/MIME encryption : No
S/MIME encryption CA : No
CRL signing : No
CRL signing CA : No
Any Purpose : Yes
Any Purpose CA : Yes
OCSP helper : Yes
OCSP helper CA : No
which makes sense now as regular purposes vs CA purposes