Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Backport][ipa-4-7] Verify external CA's basic constraint pathlen #2994

Closed
wants to merge 1 commit into from

Conversation

tiran
Copy link
Member

@tiran tiran commented Apr 4, 2019

Manual backport of PR #7877

IPA no verifies that intermediate certs of external CAs have a basic
constraint path len of at least 1 and increasing.

Fixes: https://pagure.io/freeipa/issue/7877
Signed-off-by: Christian Heimes cheimes@redhat.com
Reviewed-By: Fraser Tweedale ftweedal@redhat.com
Reviewed-By: Alexander Bokovoy abokovoy@redhat.com

IPA no verifies that intermediate certs of external CAs have a basic
constraint path len of at least 1 and increasing.

Fixes: https://pagure.io/freeipa/issue/7877
Signed-off-by: Christian Heimes <cheimes@redhat.com>
Reviewed-By: Fraser Tweedale <ftweedal@redhat.com>
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com>
@tiran tiran added the ack Pull Request approved, can be merged label Apr 4, 2019
@tiran
Copy link
Member Author

tiran commented Apr 4, 2019

Auto ACK backport

@tiran tiran added the pushed Pull Request has already been pushed label Apr 4, 2019
@tiran
Copy link
Member Author

tiran commented Apr 4, 2019

ipa-4-7:

  • 18623d4 Verify external CA's basic constraint pathlen

@tiran tiran closed this Apr 4, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ack Pull Request approved, can be merged pushed Pull Request has already been pushed
Projects
None yet
1 participant