Timestamp validation checks critical flag on EKU

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Dear OpenSSL users,

recently we checked an older timestamp using the OpenSSL Library version 1.1.1i.
The check revealed, that the timestamp verification failed.

Digging into the code we found that if an eku entry for timestamping is preset
it is expected to be marked critical (see v3_purp.c:798 ff.).

Thats's not the case for the timetamp cert in use.

We couldn'f find any source that enforces the critical flag on eku timestamp entries.
RFC 5280 says, that makring the EKU as critical is deliberate tu the issuer.

Any thoughts or pointer to the mentioned requirement?

Thanks in advance
--
Christian Weber



[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux