Completely remove the ability to configure Certificate Policy OIDs in the Boulder CA. Instead, hard-code the Baseline Requirements Domain Validated Reserved Policy Identifier. Boulder will never perform OV or EV validation, so this is the only identifier that will be necessary. In the ceremony tool, introduce additional checks that assert that Root certificates do not have policies, and Intermediate certificates have exactly the one Baseline Requirements Domain Validated Reserved Policy Identifier. |
||
|---|---|---|
| .. | ||
| generate.go | ||
| intermediate-ceremony-ecdsa.yaml | ||
| intermediate-ceremony-rsa.yaml | ||
| intermediate-key-ceremony-ecdsa.yaml | ||
| intermediate-key-ceremony-rsa.yaml | ||
| root-ceremony-ecdsa.yaml | ||
| root-ceremony-rsa.yaml | ||
| root-crl-ecdsa.yaml | ||
| root-crl-rsa.yaml | ||