Skip to content

Reject CRLs with unrecognized critical entry extensions per RFC 5280 section 5.3#10274

Open
gasbytes wants to merge 1 commit intowolfSSL:masterfrom
gasbytes:crl-idp-extension-fix-follow-up
Open

Reject CRLs with unrecognized critical entry extensions per RFC 5280 section 5.3#10274
gasbytes wants to merge 1 commit intowolfSSL:masterfrom
gasbytes:crl-idp-extension-fix-follow-up

Conversation

@gasbytes
Copy link
Copy Markdown
Contributor

Description

Reject CRLs with unrecognized critical entry extensions per RFC 5280 section 5.3.

This is a follow-up to #10239

Testing

./configure --enable-crl --enable-opensslextra --enable-debug &&
make -j8 &&
make check

The changes includes two tests covering the appropriate involved paths
The certs used in the tests are the same ones approved in #10239.

Checklist

  • added tests
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

@gasbytes gasbytes self-assigned this Apr 21, 2026
@gasbytes gasbytes assigned wolfSSL-Bot and unassigned gasbytes Apr 21, 2026
@gasbytes gasbytes marked this pull request as ready for review April 21, 2026 17:56
@github-actions
Copy link
Copy Markdown

MemBrowse Memory Report

No memory changes detected for:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants