ryankurte / pki

Scripts to bootstrap internal Certificate Authorities (CAs) using Yubikeys
MIT License
76 stars 12 forks source link

Certificate extensions not being copied into intermediate or client certs #12

Closed ryankurte closed 5 years ago

ryankurte commented 5 years ago

From https://www.openssl.org/docs/man1.1.0/man1/x509.html#BUGS:

Extensions in certificates are not transferred to certificate requests and vice versa.

Related: https://security.stackexchange.com/questions/150078/missing-x509-extensions-with-an-openssl-generated-certificate