Repository navigation
x509-cert: RequestBuilder: omit an empty extensionRequest attribute - #2455
Open
yuxi-liu-wired wants to merge 1 commit into
Open
yuxi-liu-wired wants to merge 1 commit into
yuxi-liu-wired wants to merge 1 commit into
Conversation
`RequestBuilder::finalize` always added an extensionRequest attribute,
even when no extension was added, encoding `SET { SEQUENCE {} }`.
RFC 2985 5.4.2 defines `ExtensionRequest ::= Extensions` and RFC 5280
defines `Extensions ::= SEQUENCE SIZE (1..MAX) OF Extension`, so an empty
one is not valid. OpenSSL (`openssl req -new` without extensions) and
pyca/cryptography leave the attribute out.
Only add the attribute when there is at least one extension.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
RequestBuilder::finalizealways adds anextensionRequestattribute, even when no extension was added. The attribute then holds an empty sequence:RFC 2985 5.4.2 defines
ExtensionRequest ::= Extensions, and RFC 5280 4.1 definesExtensions ::= SEQUENCE SIZE (1..MAX) OF Extension, so an empty extension request is outside the schema.openssl req -newwithout extensions, and pyca/cryptography's CSR builder, both leave the attribute out.This PR only adds the attribute when there is at least one extension.
Test:
certificate_request_extension_req_only_when_extensionschecks that a request without extensions has no extensionRequest attribute, and that one with a SubjectAltName has exactly one. The first assertion fails on master.This PR was produced by AI agents (Claude) while reviewing
x509-certcode that the differential fuzzing ofder/x509-certdoes not reach.