We currently only enforce Name Constraints on the leaf SANs, while according to RFC 5280, Section 6.1.3(b), we should also enforce it on intermediates with SANs. No security impact on WebPKI-like cases, but also no expected breakage.
/cc @rolandshoemaker
We currently only enforce Name Constraints on the leaf SANs, while according to RFC 5280, Section 6.1.3(b), we should also enforce it on intermediates with SANs. No security impact on WebPKI-like cases, but also no expected breakage.
/cc @rolandshoemaker