Sitelet https://github.com/RustCrypto/formats/pull/2456
Skip to content

x509-cert: CrlBuilder: omit an empty revokedCertificates list - #2456

Open
yuxi-liu-wired wants to merge 1 commit into
RustCrypto:masterfrom
yuxi-liu-wired:fix/crl-builder-omit-empty-revoked
Open

yuxi-liu-wired wants to merge 1 commit into
RustCrypto:masterfrom
yuxi-liu-wired:fix/crl-builder-omit-empty-revoked

Conversation

@yuxi-liu-wired

Copy link
Copy Markdown
Contributor

RFC 5280 5.1.2.6 says: "When there are no revoked certificates, the revoked certificates list MUST be absent." CrlBuilder::with_certificates sets revoked_certificates to Some(..) before collecting the iterator. With no revoked certificates (an empty iterator), the CRL therefore carries an empty revokedCertificates SEQUENCE {}, which the RFC forbids.

This PR drops an empty list in finalize, before the TBS is encoded and signed.

Test: crl_without_revoked_certificates builds a CRL with with_certificates(core::iter::empty()) and expects revoked_certificates == None. It fails on master (Some([])).

This PR was produced by AI agents (Claude) while reviewing x509-cert code that the differential fuzzing of der/x509-cert does not reach.

RFC 5280 5.1.2.6: "When there are no revoked certificates, the revoked
certificates list MUST be absent." `CrlBuilder::with_certificates` with an
empty iterator set `revoked_certificates` to `Some(vec![])`, which encodes
an empty `SEQUENCE {}` in the CRL.

Drop an empty list in `finalize`, before the TBS is encoded and signed.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant