New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: add check for unsupported subject fields #275
fix: add check for unsupported subject fields #275
Conversation
verifier/verifier.go
Outdated
|
||
// identities containing "=#" can cause memory issues in the asn1-ber library used by | ||
// pkix when parsing the DN | ||
if strings.Contains(identityValue, "=#") { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
adding this to pkix instead
Codecov Report
📣 This organization is not using Codecov’s GitHub App Integration. We recommend you install it so Codecov can continue to function properly for your repositories. Learn more @@ Coverage Diff @@
## main #275 +/- ##
==========================================
+ Coverage 73.37% 73.67% +0.30%
==========================================
Files 23 23
Lines 1994 1994
==========================================
+ Hits 1463 1469 +6
+ Misses 429 425 -4
+ Partials 102 100 -2
📣 We’re building smart automated test selection to slash your CI/CD build times. Learn more |
115dbb1
to
9d094e5
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
5fd1ccb
to
c669dcf
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
760aab5
91157ac
to
760aab5
Compare
Signed-off-by: Byron Chien <byronc@ucla.edu>
Signed-off-by: Byron Chien <byronc@ucla.edu>
Signed-off-by: Byron Chien <byronc@ucla.edu>
760aab5
to
27798ef
Compare
Signed-off-by: Byron Chien <byronc@ucla.edu>
876a3b1
to
1362f46
Compare
Signed-off-by: Byron Chien <byronc@ucla.edu>
1362f46
to
cac9f1a
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Fails trusted identity verification if the trust policy identity or the subject of the leaf certificate contains "=#".
example logs:
Signed-off-by: Byron Chien chienb@amazon.com