Skip to content

Check the CRL issuer name against the signing CA - #11476

Open
padelsbach wants to merge 1 commit into
wolfSSL:masterfrom
padelsbach:verify-crle
Open

padelsbach wants to merge 1 commit into
wolfSSL:masterfrom
padelsbach:verify-crle

Conversation

@padelsbach

Copy link
Copy Markdown
Contributor

Description

VerifyCRLE() picked the signing CA from the AKID without checking that the CA has the issuer name from the CRL. Adds the check from PaseCRL_CheckSignature().

Testing

Added unit test

Checklist

  • added tests
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11476

Scan targets checked: wolfssl-src, wolfssl-bugs

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants