commit | fed2be428f769650ca07c3858ef40880bba2ed18 | [log] [tgz] |
---|---|---|
author | Shawn Willden <swillden@google.com> | Mon Apr 25 08:59:48 2016 -0600 |
committer | Shawn Willden <swillden@google.com> | Mon Apr 25 08:59:48 2016 -0600 |
tree | 46397fde30dba966a30fd10e28f99724b47e5c55 | |
parent | 637dd8429285bfdc0b89622476ea94d782b1eb14 [diff] |
Add authority key ID to attestation certificates. The attestation certificate chain produced by softkeymaster is hard to verify because the leaf certificate does not contain the X509v3 Key Authority ID extension, which provides the ID of the signing key. This isn't strictly required by the standard, but many tools get badly confused without the ID extension, including openssl. Bug: 28321678 Change-Id: I91136f08eaf0b81b5443753488beb8a40af60e6c