summaryrefslogtreecommitdiffstats
path: root/pki/base/ca/shared/profiles/ca/caDualCert.cfg
diff options
context:
space:
mode:
authorjmagne <jmagne@c9f7a03b-bd48-0410-a16d-cbbf54688b0b>2010-10-28 23:18:58 +0000
committerjmagne <jmagne@c9f7a03b-bd48-0410-a16d-cbbf54688b0b>2010-10-28 23:18:58 +0000
commit440440addf3512ad7c7d08d7d8e4245a9f2cee8f (patch)
tree26dd1b46b843f068497cc40c9add4eed50d16150 /pki/base/ca/shared/profiles/ca/caDualCert.cfg
parent34811f61a8a8b2628cfcb5350b86a172692393e3 (diff)
downloadpki-440440addf3512ad7c7d08d7d8e4245a9f2cee8f.tar.gz
pki-440440addf3512ad7c7d08d7d8e4245a9f2cee8f.tar.xz
pki-440440addf3512ad7c7d08d7d8e4245a9f2cee8f.zip
Fix Bugzilla Bug 524916 - ECC key constraints plug-ins should be based on ECC curve names (not on key sizes).
git-svn-id: svn+ssh://svn.fedorahosted.org/svn/pki/trunk@1448 c9f7a03b-bd48-0410-a16d-cbbf54688b0b
Diffstat (limited to 'pki/base/ca/shared/profiles/ca/caDualCert.cfg')
-rw-r--r--pki/base/ca/shared/profiles/ca/caDualCert.cfg8
1 files changed, 3 insertions, 5 deletions
diff --git a/pki/base/ca/shared/profiles/ca/caDualCert.cfg b/pki/base/ca/shared/profiles/ca/caDualCert.cfg
index 78b73a8e4..f85c70f41 100644
--- a/pki/base/ca/shared/profiles/ca/caDualCert.cfg
+++ b/pki/base/ca/shared/profiles/ca/caDualCert.cfg
@@ -30,9 +30,8 @@ policyset.encryptionCertSet.2.default.params.range=180
policyset.encryptionCertSet.2.default.params.startTime=0
policyset.encryptionCertSet.3.constraint.class_id=keyConstraintImpl
policyset.encryptionCertSet.3.constraint.name=Key Constraint
-policyset.encryptionCertSet.3.constraint.params.keyType=-
-policyset.encryptionCertSet.3.constraint.params.keyMinLength=256
-policyset.encryptionCertSet.3.constraint.params.keyMaxLength=4096
+policyset.encryptionCertSet.3.constraint.params.keyType=RSA
+policyset.encryptionCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096
policyset.encryptionCertSet.3.default.class_id=userKeyDefaultImpl
policyset.encryptionCertSet.3.default.name=Key Default
policyset.encryptionCertSet.4.constraint.class_id=noConstraintImpl
@@ -114,8 +113,7 @@ policyset.signingCertSet.2.default.params.startTime=60
policyset.signingCertSet.3.constraint.class_id=keyConstraintImpl
policyset.signingCertSet.3.constraint.name=Key Constraint
policyset.signingCertSet.3.constraint.params.keyType=RSA
-policyset.signingCertSet.3.constraint.params.keyMinLength=512
-policyset.signingCertSet.3.constraint.params.keyMaxLength=4096
+policyset.signingCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096
policyset.signingCertSet.3.default.class_id=userKeyDefaultImpl
policyset.signingCertSet.3.default.name=Key Default
policyset.signingCertSet.4.constraint.class_id=noConstraintImpl