Clarify documentation of mbedtls_x509_crt_profile

This commit fixes #1992: The documentation of mbedtls_x509_crt_profile
previously stated that the bitfield `allowed_pks` defined which signature
algorithms shall be allowed in CRT chains. In actual fact, however,
the field also applies to guard the public key of the end entity
certificate.

This commit changes the documentation to state that `allowed_pks`
applies to the public keys of all CRTs in the provided chain.

Signed-off-by: Manuel Pégourié-Gonnard <manuel.pegourie-gonnard@arm.com>
This commit is contained in:
Hanno Becker 2018-10-11 11:36:29 +01:00 committed by Manuel Pégourié-Gonnard
parent a2da9c7e45
commit 2b9fb88281

View File

@ -190,7 +190,9 @@ mbedtls_x509_subject_alternative_name;
typedef struct mbedtls_x509_crt_profile typedef struct mbedtls_x509_crt_profile
{ {
uint32_t allowed_mds; /**< MDs for signatures */ uint32_t allowed_mds; /**< MDs for signatures */
uint32_t allowed_pks; /**< PK algs for signatures */ uint32_t allowed_pks; /**< PK algs for public keys;
* this applies to any CRT
* in the provided chain. */
uint32_t allowed_curves; /**< Elliptic curves for ECDSA */ uint32_t allowed_curves; /**< Elliptic curves for ECDSA */
uint32_t rsa_min_bitlen; /**< Minimum size for RSA keys */ uint32_t rsa_min_bitlen; /**< Minimum size for RSA keys */
} }