Skip to content

Commit

Permalink
tls: allow certificates to be used for codesigning
Browse files Browse the repository at this point in the history
  • Loading branch information
tinyzimmer committed Nov 7, 2023
1 parent abd61dd commit 48eb812
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions pkg/crypto/tlscerts.go
Original file line number Diff line number Diff line change
Expand Up @@ -306,7 +306,7 @@ func GenerateCA(cfg CACertConfig) (privkey crypto.PrivateKey, cert *x509.Certifi
NotBefore: time.Now().UTC(),
NotAfter: time.Now().UTC().Add(cfg.ValidFor),
IsCA: true,
ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageClientAuth, x509.ExtKeyUsageServerAuth},
ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageClientAuth, x509.ExtKeyUsageServerAuth, x509.ExtKeyUsageCodeSigning},
KeyUsage: x509.KeyUsageDigitalSignature | x509.KeyUsageCertSign,
BasicConstraintsValid: true,
}
Expand Down Expand Up @@ -382,7 +382,7 @@ func IssueCertificate(cfg IssueConfig) (privkey crypto.PrivateKey, cert *x509.Ce
NotBefore: time.Now().UTC(),
NotAfter: time.Now().UTC().Add(cfg.ValidFor),
IsCA: false,
ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageClientAuth, x509.ExtKeyUsageServerAuth},
ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageClientAuth, x509.ExtKeyUsageServerAuth, x509.ExtKeyUsageCodeSigning},
KeyUsage: x509.KeyUsageDigitalSignature,
BasicConstraintsValid: true,
}
Expand Down

0 comments on commit 48eb812

Please sign in to comment.