Re: PKCS7 verification with CA hierarchy

Heikki Toivonen <[email protected]>
Newsgroups gmane.comp.python.cryptography
Message-ID <[email protected]>
Sébastien Merle wrote:
> If the signer has been issued by another sub CA
> or if the signer has been issued directly by
> the root CA, I want the verification to fail,
> even if the pkc7 contains its own certification chain.

Hmm, I am not completely sure I understood what you want.

> How could I do this in python ? Is it even possible ?

Can you do it using C and OpenSSL? If the answer is yes, then there is a
very high likelyhood you can do it with M2Crypto. The only problem I
could see (beyond bugs of course) is that some OpenSSL API you'd need
has not yet been wrapped. If that turns out to be the case I'd be happy
to wrap the needed API(s) and include them in the next release.

-- 
  Heikki Toivonen
signature.asc (application/pgp-signature, 252 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFHVE1Jb8x8KoP+JuwRApQzAJ94Dsd2hHUS0lby7NOnewT2T7C69wCfR4cy
3LhkUk/luNq4v3fqBkkEbV4=
=5j5z
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.