func checkForIsCa(name string, sec *keyStore.KeyStore) error { if !sec.IsCA() { return errors.New("It is not possible to generate a new certificate for service '%v' with a caretakerd certificate that is not a CA. "+ "Use trusted access for service '%v', configure caretakerd to generate its own certificate or provide a CA enabled certificate for caretakerd.", name, name) } return nil }