Skip to content

verify_cert: exclude self-issued CAs from path length - #539

Closed
Beafly wants to merge 1 commit into
rustls:mainfrom
Beafly:fix/self-issued-pathlen
Closed

Beafly wants to merge 1 commit into
rustls:mainfrom
Beafly:fix/self-issued-pathlen

Conversation

@Beafly

@Beafly Beafly commented Sep 26, 2026

Copy link
Copy Markdown

Fixes #538.

RFC 5280 section 6.1.4(m) applies its path length decrement only when the
certificate is not self-issued. PathBuilder tracks the equivalent constraint
with sub_ca_count, but currently increments the count for every certificate in
the issuer role. A self-issued intermediate CA therefore consumes its parent's
pathLenConstraint allowance.

This changes path length accounting to increment only when the current issuer
certificate is not self-issued (issuer != subject).

The regression tests build this chain and assert the exact path selected:

end entity -> child CA -> constrained parent CA -> trust anchor

They cover four cases:

  • self-issued child, parent pathLenConstraint=0: succeeds;
  • self-issued child, parent pathLenConstraint=1: succeeds;
  • non-self-issued child, parent pathLenConstraint=0: fails with
    PathLenConstraintViolated;
  • non-self-issued child, parent pathLenConstraint=1: succeeds.

The self-issued child uses a distinct key and a subject name equal to its issuer
name. An independent OpenSSL 3.6.3 verify -x509_strict control produces the
same four results.

The error-ranking behavior described in #538 is intentionally unchanged.

Validation completed locally with the repository's formatting, Clippy,
documentation, package, feature-matrix test, MSRV, no-std, and feature-powerset
commands.

@codecov

codecov Bot commented Sep 26, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.66%. Comparing base (3d0adc4) to head (90b7568).

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #539      +/-   ##
==========================================
+ Coverage   97.63%   97.66%   +0.02%     
==========================================
  Files          20       20              
  Lines        4106     4152      +46     
==========================================
+ Hits         4009     4055      +46     
  Misses         97       97              

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Comment thread src/verify_cert.rs
));
}

#[test]

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not yet convinced this is a change worth making (see my comment here), but I wanted to flag that if the consensus is that this is the right change, we should also be removing the x509-limbo pathlen::self-issued-certs-pathlen testcase exception:

"pathlen::self-issued-certs-pathlen": {
"expected": "SUCCESS",
"actual": "FAILURE",
"reason": "webpki does not support self-signed certificates"
},

@Beafly

Beafly commented Sep 27, 2026

Copy link
Copy Markdown
Author

Thanks for the explanation. I understand the reasoning now, and I don’t have a production PKI case that requires this behavior. I’m closing the issue and PR.

@Beafly Beafly closed this Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

pathLenConstraint appears to count self-issued intermediate CA

2 participants