RFC5280Policy
A VerifierPolicy that implements the core chain verifying policies from RFC 5280.
- iOS
- 13+
- macOS
- 10.15+
- Mac Catalyst
- 13+
- tvOS
- 13+
- visionOS
- 1.0+
- watchOS
- 6+
struct RFC5280PolicyAlmost all verifiers should use this policy as the initial component of their policy set. The policy checks the following things:
Version.
v1Certificates withExtensionsare rejected.Expiry. Expired certificates are rejected.
Basic Constraints. Police the constraints contained in the
BasicConstraintsextension.Name Constraints. Police the constraints contained in the
NameConstraintsextension.