Open Bug 430378 Opened 17 years ago Updated 3 years ago

vfychain usage should be corrected to show nicknames are supported

Categories

(NSS :: Tools, defect, P2)

Tracking

(Not tracked)

People

(Reporter: julien.pierre, Unassigned)

Details

vfychain only supports external files on the command-line . It should also allow nicknames, so that certs already in a database/token can be used, rather than having to be extracted to a file before verification.
Of course, since all the certs for a bridge (or cross signed CA) have the same subject name, they all have the same nickname. Therefore, when a bridge has multiple certs, and more than one of them is in the cert DB, it is not possible to specify a particular one of those certs using nicknames. There are test cases where you want to specify a particular chain exactly, such as (especially) in negative testing. It is possible to create a different cert DB for each chain for testing, but that is very cumbersome. Still, it would be useful if the -t option could specify anchors by nickname.
Severity: normal → enhancement
Priority: -- → P3
Summary: vfychain does not support nicknames → vfychain should support nicknames in addition to file names
Nelson, I wasn't only talking about the -t option . It is not possible to specify the EE cert by nickname either. That means in 100% of the cases of using vfychain, even if you aren't using PKIX or bridge CAs, you have to use an external file. I find that unacceptable now that vfychain has become our tool of choice for cert verification. It should conform to the rest of NSS and support the database at least minimally.
Priority: P3 → P2
It turns out the feature is in. But it is undocumented. The usage message needs to be fixed.
Severity: enhancement → normal
Summary: vfychain should support nicknames in addition to file names → vfychain usage should be corrected to show nicknames are supported

The bug assignee is inactive on Bugzilla, and this bug has priority 'P2'.
:beurdouche, could you have a look please?

For more information, please visit auto_nag documentation.

Assignee: alvolkov.bgs → nobody
Flags: needinfo?(bbeurdouche)
Severity: normal → S3

We have modified the bot to only consider P1 as high priority, so I'm cancelling the needinfo here.

Flags: needinfo?(bbeurdouche)
You need to log in before you can comment on or make changes to this bug.