cmpv2: PkiFailureInfoValues are bit masks - #2470
Open
yuxi-liu-wired wants to merge 1 commit into
Open
yuxi-liu-wired wants to merge 1 commit into
yuxi-liu-wired wants to merge 1 commit into
Conversation
flagset discriminants are bit masks (as in x509-cert's KeyUsages and Reasons), but PkiFailureInfoValues used the RFC 4210 bit numbers as values: BadAlg = 0 (the empty set), BadMessageCheck = 1 (bit 0), BadRequest = 2 (bit 1), BadTime = 3 (bits 0 and 1), and so on. Every failInfo was decoded and encoded wrong. An OpenSSL error response with failInfo badRequest (03 02 05 20, bit 2) decoded as BadAlg | BadCertId, and FlagSet::from(BadAlg) encoded as an empty BIT STRING. Use a shift of n for RFC bit n.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
flagsetdiscriminants are bit masks;x509-cert'sKeyUsages,ReasonsandCertPoliciesuse1 << n. ButPkiFailureInfoValuesuses the RFC 4210 bit numbers as the values:So every
failInfois decoded and encoded wrong. That affects CMP responses, and alsox509-tsp'sTimeStampRespstatus, which uses the samePkiStatusInfo.tests/examples/failed_kur_rsp_01.binis an OpenSSL error response with statusString "wrong certid" and failInfo03 02 05 20(bit 2, badRequest). It decodes asBadAlg | BadCertId.PkiFailureInfo::from(BadAlg)encodes as03 01 00, an empty BIT STRING.PkiFailureInfo::from(BadMessageCheck)encodes as03 02 07 80, which is badAlg on the wire.The fix uses
1 << nfor RFC bitn. Values in aFlagSetbuilt with the old discriminants change meaning, but anything built by name (PkiFailureInfoValues::BadPOP.into()) now encodes what the name says.Tests:
tests/failure_info.rschecks six values in both directions against their RFC bit positions, includingbadAlg(bit 0) andduplicateCertReq(bit 26). It also checks the OpenSSL response above decodes asBadRequest. Both tests fail on master. Thecmpv2.ymlmatrix passed locally: powerset tests on stable and 1.85, thumbv7em powerset build, fmt, clippy.Found by decoding the messages from an
openssl cmp -use_mock_srvexchange with-failure/-failurebits.This PR was produced by AI agents (Claude) and reviewed by me before submission.