Skip to content

Commit 097db5b

Browse files
committed
log certificate serial numbers
1 parent ec1e4cf commit 097db5b

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

Diff for: ici_acme/policy/x509.py

+3-2
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ def _add_ca_cert(store, fn: str):
2020
with open(fn, 'rb') as fd:
2121
_ca = crypto.load_certificate(crypto.FILETYPE_PEM, fd.read())
2222
store.add_cert(_ca)
23-
logger.debug(f'Added CA cert from file {fn}: {_ca.get_subject()}')
23+
logger.debug(f'Added CA cert from file {fn}: {_ca.get_subject()} (serial {_ca.get_serial_number()})')
2424

2525

2626
def is_valid_x509_cert(client_cert: X509, ca_path: str) -> bool:
@@ -38,7 +38,8 @@ def is_valid_x509_cert(client_cert: X509, ca_path: str) -> bool:
3838
else:
3939
raise RuntimeError(f'CA path {repr(ca_path)} is not a file or directory')
4040

41-
logger.debug(f'Validating certificate {client_cert.get_subject()}, issued by {client_cert.get_issuer()}')
41+
logger.debug(f'Validating certificate {client_cert.get_subject()} (serial {client_cert.get_serial_number()}), '
42+
f'issued by {client_cert.get_issuer()}')
4243
ctx = crypto.X509StoreContext(store, client_cert)
4344
try:
4445
result = ctx.verify_certificate()

0 commit comments

Comments
 (0)