Sitelet https://github.com/RustCrypto/formats/pull/2470
Skip to content

cmpv2: PkiFailureInfoValues are bit masks - #2470

Open
yuxi-liu-wired wants to merge 1 commit into
RustCrypto:masterfrom
yuxi-liu-wired:fix/cmpv2-failure-info-bits
Open

yuxi-liu-wired wants to merge 1 commit into
RustCrypto:masterfrom
yuxi-liu-wired:fix/cmpv2-failure-info-bits

Conversation

@yuxi-liu-wired

Copy link
Copy Markdown
Contributor

flagset discriminants are bit masks; x509-cert's KeyUsages, Reasons and CertPolicies use 1 << n. But PkiFailureInfoValues uses the RFC 4210 bit numbers as the values:

BadAlg = 0,          // the empty set
BadMessageCheck = 1, // bit 0
BadRequest = 2,      // bit 1
BadTime = 3,         // bits 0 and 1
BadCertId = 4,       // bit 2
...

So every failInfo is decoded and encoded wrong. That affects CMP responses, and also x509-tsp's TimeStampResp status, which uses the same PkiStatusInfo.

  • tests/examples/failed_kur_rsp_01.bin is an OpenSSL error response with statusString "wrong certid" and failInfo 03 02 05 20 (bit 2, badRequest). It decodes as BadAlg | BadCertId.
  • PkiFailureInfo::from(BadAlg) encodes as 03 01 00, an empty BIT STRING.
  • PkiFailureInfo::from(BadMessageCheck) encodes as 03 02 07 80, which is badAlg on the wire.

The fix uses 1 << n for RFC bit n. Values in a FlagSet built with the old discriminants change meaning, but anything built by name (PkiFailureInfoValues::BadPOP.into()) now encodes what the name says.

Tests: tests/failure_info.rs checks six values in both directions against their RFC bit positions, including badAlg (bit 0) and duplicateCertReq (bit 26). It also checks the OpenSSL response above decodes as BadRequest. Both tests fail on master. The cmpv2.yml matrix passed locally: powerset tests on stable and 1.85, thumbv7em powerset build, fmt, clippy.

Found by decoding the messages from an openssl cmp -use_mock_srv exchange with -failure/-failurebits.

This PR was produced by AI agents (Claude) and reviewed by me before submission.

flagset discriminants are bit masks (as in x509-cert's KeyUsages and
Reasons), but PkiFailureInfoValues used the RFC 4210 bit numbers as
values: BadAlg = 0 (the empty set), BadMessageCheck = 1 (bit 0),
BadRequest = 2 (bit 1), BadTime = 3 (bits 0 and 1), and so on. Every
failInfo was decoded and encoded wrong. An OpenSSL error response with
failInfo badRequest (03 02 05 20, bit 2) decoded as BadAlg | BadCertId,
and FlagSet::from(BadAlg) encoded as an empty BIT STRING.

Use a shift of n for RFC bit n.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant