Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #539 +/- ##
==========================================
+ Coverage 97.63% 97.66% +0.02%
==========================================
Files 20 20
Lines 4106 4152 +46
==========================================
+ Hits 4009 4055 +46
Misses 97 97 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
| )); | ||
| } | ||
|
|
||
| #[test] |
There was a problem hiding this comment.
I'm not yet convinced this is a change worth making (see my comment here), but I wanted to flag that if the consensus is that this is the right change, we should also be removing the x509-limbo pathlen::self-issued-certs-pathlen testcase exception:
webpki/third-party/x509-limbo/exceptions.json
Lines 7 to 11 in 3d0adc4
|
Thanks for the explanation. I understand the reasoning now, and I don’t have a production PKI case that requires this behavior. I’m closing the issue and PR. |
Fixes #538.
RFC 5280 section 6.1.4(m) applies its path length decrement only when the
certificate is not self-issued.
PathBuildertracks the equivalent constraintwith
sub_ca_count, but currently increments the count for every certificate inthe issuer role. A self-issued intermediate CA therefore consumes its parent's
pathLenConstraintallowance.This changes path length accounting to increment only when the current issuer
certificate is not self-issued (
issuer != subject).The regression tests build this chain and assert the exact path selected:
They cover four cases:
pathLenConstraint=0: succeeds;pathLenConstraint=1: succeeds;pathLenConstraint=0: fails withPathLenConstraintViolated;pathLenConstraint=1: succeeds.The self-issued child uses a distinct key and a subject name equal to its issuer
name. An independent OpenSSL 3.6.3
verify -x509_strictcontrol produces thesame four results.
The error-ranking behavior described in #538 is intentionally unchanged.
Validation completed locally with the repository's formatting, Clippy,
documentation, package, feature-matrix test, MSRV, no-std, and feature-powerset
commands.