Skip to content

Harden PKIX path validation and support trusted certificate PEM blocks - #206

Merged
Xor-el merged 1 commit into
masterfrom
feature/pkix-validation-and-trusted-cert-pem
Sep 30, 2026
Merged

Xor-el merged 1 commit into
masterfrom
feature/pkix-validation-and-trusted-cert-pem

Conversation

@Xor-el

@Xor-el Xor-el commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Summary

Hardens certification path validation and building, and adds read/write support
for TRUSTED CERTIFICATE PEM blocks. Also tightens a few related surfaces
(trust-anchor comparison, ECDH KEK shared info).

Path validation and building

  • Restrict CRL-signer validation to the supplied trust anchors and report the
    real failure per RFC 5280 sec. 6.3.3 (f). When the certificate's own
    distribution-point CRLs are tried first and fail, that context is chained into
    the final message instead of being lost.
  • Count path length excluding self-issued intermediates, so a rolled root or an
    indirect CRL-signer chain is bounded correctly.
  • Narrow the active parameters to the resolved trust anchor during validation,
    and raise when the resolved anchor is not among those supplied.
  • Honour excluded certificates when building a path.
  • Raise a recoverable error when no CRLs are found, rather than looping when two
    CAs share a CRL-issuer distinguished name.
  • Find the trust anchor by comparing the CA and subject by value, preserving the
    first failure reason.

Trust anchor and ECDH KEK

  • Compare the trust-anchor CA by value and drop the string CA-name form; callers
    and results now use CA.ToString().
  • Include the optional entityUInfo in the ECDH KEK shared info.

OpenSSL PEM

  • Read and write TRUSTED CERTIFICATE blocks (an X509 trusted certificate block
    wrapping the certificate plus an optional certificate trust block).

Tests

  • Add CertPathHardeningTests covering the shared-CRL-issuer loop case and the
    indirect CRL-signer paths (single generation, rolled root, excluded signer,
    and maximum-path-length bounds).
  • Add an OpenSSL trusted-certificate round-trip and an EdDSA private-key read,
    loading the key from the test data folder.
  • Assert the trust-anchor CA round-trips via CA.ToString().

Path validation and building:
- Restrict CRL-signer validation to the supplied trust anchors and report
  the real failure per RFC 5280 sec. 6.3.3 (f); when the distribution-point
  CRLs are tried first and fail, chain that context into the message.
- Count path length excluding self-issued intermediates so a rolled root
  or an indirect CRL-signer chain is bounded correctly.
- Narrow the active parameters to the resolved trust anchor during
  validation, and raise when the resolved anchor is not among those supplied.
- Honour excluded certificates when building, and raise a recoverable error
  when no CRLs are found instead of looping on a shared issuer DN.
- Find the trust anchor by comparing the CA and subject by value, preserving
  the first failure reason.

Trust anchor and KEK:
- Compare the trust-anchor CA by value and drop the string CA-name form;
  callers and results use CA.ToString().
- Include the optional entityUInfo in the ECDH KEK shared info.

OpenSSL PEM:
- Read and write TRUSTED CERTIFICATE blocks (X509 trusted certificate block
  and certificate trust block).

Tests:
- Add CertPathHardeningTests covering the shared-CRL-issuer loop case and the
  indirect CRL-signer paths (single generation, rolled root, excluded signer,
  and path-length bounds).
- Add OpenSSL trusted-certificate round-trip and an EdDSA private-key read,
  loading the key from the test data folder.
- Assert the trust-anchor CA round-trips via CA.ToString().
@Xor-el
Xor-el merged commit cd92b89 into master Sep 30, 2026
42 checks passed
@Xor-el
Xor-el deleted the feature/pkix-validation-and-trusted-cert-pem branch September 30, 2026 12:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant