From 253929a85c45c1313fd68d10ec7a7a45e380d5c0 Mon Sep 17 00:00:00 2001 From: Paul Kehrer Date: Wed, 5 Aug 2015 17:30:39 +0100 Subject: add AuthorityKeyIdentifier from_issuer_public_key Refactored SKI's creation code into a separate function, added doctest examples --- docs/x509/reference.rst | 30 ++++++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) (limited to 'docs/x509/reference.rst') diff --git a/docs/x509/reference.rst b/docs/x509/reference.rst index dfa91fac..a05be164 100644 --- a/docs/x509/reference.rst +++ b/docs/x509/reference.rst @@ -1160,6 +1160,28 @@ X.509 Extensions The serial number of the issuer's issuer. + .. classmethod:: from_issuer_public_key(public_key) + + .. versionadded:: 1.0 + + Creates a new AuthorityKeyIdentifier instance using the public key + provided to generate the appropriate digest. This should be the + **issuer public key**. The resulting object will contain a + :attr:`~cryptography.x509.AuthorityKeyIdentifier.key_identifier`. + The generated digest is the SHA1 hash of the ``subjectPublicKey`` A + SN.1 bit string. This is the first recommendation in :rfc:`5280` + section 4.2.1.2. + + :param certificate: The issuing :class:`~cryptography.x509.Certificate`. + + .. doctest:: + + >>> from cryptography import x509 + >>> from cryptography.hazmat.backends import default_backend + >>> cert = x509.load_pem_x509_certificate(pem_data, default_backend()) + >>> x509.AuthorityKeyIdentifier.from_issuer_public_key(cert.public_key()) + + .. class:: SubjectKeyIdentifier .. versionadded:: 0.9 @@ -1198,6 +1220,14 @@ X.509 Extensions , or :class:`~cryptography.hazmat.primitives.asymmetric.ec.EllipticCurvePublicKey`. + .. doctest:: + + >>> from cryptography import x509 + >>> from cryptography.hazmat.backends import default_backend + >>> cert = x509.load_pem_x509_certificate(pem_data, default_backend()) + >>> x509.SubjectKeyIdentifier.from_public_key(cert.public_key()) + + .. class:: SubjectAlternativeName .. versionadded:: 0.9 -- cgit v1.2.3