Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

No possibility to rekey over simplereenroll endpoint #113

Open
stbenz opened this issue May 30, 2022 · 0 comments
Open

No possibility to rekey over simplereenroll endpoint #113

stbenz opened this issue May 30, 2022 · 0 comments

Comments

@stbenz
Copy link

stbenz commented May 30, 2022

Hello,

As far as I can see, the only possibility to use the simplereenroll endpoint of an EST server (as specified in section 4.2.2 of RFC 7030) is through the est_client_reenroll API function.

This function calls X509_check_private_key to check that the passed private key belongs to the passed certificate, which prevents passing a new private key to perform a "rekey" operation as specified in section 4.2.2 of RFC 7030.

I already saw the similar issue #90, but the solution to use the simpleenroll endpoint might not be applicable, if for example the EST server provider doesn't provide the same authentication and/or check mechanisms in the simpleenroll endpoint as in the simplereenroll endpoint.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant