Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

observer: Add issuingDistributionPoint checking to CRL prober #7527

Open
aarongable opened this issue Jun 4, 2024 · 0 comments
Open

observer: Add issuingDistributionPoint checking to CRL prober #7527

aarongable opened this issue Jun 4, 2024 · 0 comments

Comments

@aarongable
Copy link
Contributor

When boulder-observer is configured to probe a CRL URL, it says that probing failed if it fails to read a response, or if it failed to parse the CRL. However, it is possible for the wrong CRL to be served by that URL, which is just as bad of an error (and compliance violation).

It would be good for the prober to confirm that the URL from which it fetched the CRL appears in the CRL's issuingDistributionPoint extension.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant