Backout CertPath EKU check in CA certificates

XMLWordPrintable

    • Type: Bug
    • Resolution: Fixed
    • Priority: P4
    • 1.4.2
    • Affects Version/s: 1.4.2
    • Component/s: security-libs
    • mantis
    • generic
    • generic
    • Verified

      With 4636027 we introduced an extended key usage check in CA certificates. If they contain the EKU extension, they are only allowed if they include the anyExtendedKeyUsage value. This was in response to changes in PKIX RFC3280.

      It turns out that this is an incorrect interpretation of RFC3280, which is somewhat unclear in this respect. One of the authors (Russ Housley) clarified that the EKU extension should be ignored in CA certificates.

            Assignee:
            Andreas Sterbenz
            Reporter:
            Andreas Sterbenz
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: