Skip to content

x509-cert: RequestBuilder: omit an empty extensionRequest attribute - #2455

Open
yuxi-liu-wired wants to merge 1 commit into
RustCrypto:masterfrom
yuxi-liu-wired:fix/csr-builder-omit-empty-extension-req
Open

yuxi-liu-wired wants to merge 1 commit into
RustCrypto:masterfrom
yuxi-liu-wired:fix/csr-builder-omit-empty-extension-req

Conversation

@yuxi-liu-wired

Copy link
Copy Markdown
Contributor

RequestBuilder::finalize always adds an extensionRequest attribute, even when no extension was added. The attribute then holds an empty sequence:

$ openssl asn1parse -in csr.pem     # RequestBuilder::new(..).build(..) with no extensions
  121:d=4  hl=2 l=   9 prim: OBJECT            :Extension Request
  132:d=4  hl=2 l=   2 cons: SET
  134:d=5  hl=2 l=   0 cons: SEQUENCE           <- empty

RFC 2985 5.4.2 defines ExtensionRequest ::= Extensions, and RFC 5280 4.1 defines Extensions ::= SEQUENCE SIZE (1..MAX) OF Extension, so an empty extension request is outside the schema. openssl req -new without extensions, and pyca/cryptography's CSR builder, both leave the attribute out.

This PR only adds the attribute when there is at least one extension.

Test: certificate_request_extension_req_only_when_extensions checks that a request without extensions has no extensionRequest attribute, and that one with a SubjectAltName has exactly one. The first assertion fails on master.

This PR was produced by AI agents (Claude) while reviewing x509-cert code that the differential fuzzing of der/x509-cert does not reach.

`RequestBuilder::finalize` always added an extensionRequest attribute,
even when no extension was added, encoding `SET { SEQUENCE {} }`.
RFC 2985 5.4.2 defines `ExtensionRequest ::= Extensions` and RFC 5280
defines `Extensions ::= SEQUENCE SIZE (1..MAX) OF Extension`, so an empty
one is not valid. OpenSSL (`openssl req -new` without extensions) and
pyca/cryptography leave the attribute out.

Only add the attribute when there is at least one extension.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant