Sitelet https://github.com/jruby/jruby/issues/1691
Skip to content

OpenSSL::X509::CertificateError when signing #1691

Description

@Zapotek

Hey folks,

There's inconsistent behaviour between MRI and JRuby when signing a certificate:

Code:

require 'openssl'

context = OpenSSL::SSL::SSLContext.new
context.verify_mode = OpenSSL::SSL::VERIFY_NONE

context.key             = OpenSSL::PKey::RSA.new( 2048 )
context.cert            = OpenSSL::X509::Certificate.new
context.cert.subject    = OpenSSL::X509::Name.new( [['CN', 'localhost']] )
context.cert.issuer     = context.cert.subject
context.cert.public_key = context.key
context.cert.not_before = Time.now
context.cert.not_after  = Time.now + 60 * 60 * 24

context.cert.sign( context.key, OpenSSL::Digest::SHA1.new )

MRI 2.1.1: No error.

JRuby (jruby 1.7.12 (2.0.0p195) 2014-04-15 643e292 on Java HotSpot(TM) 64-Bit Server VM 1.6.0_32-b05 [linux-amd64]):

org/jruby/ext/openssl/X509Cert.java:434:in `sign': not all mandatory fields set in V3 TBScertificate generator (OpenSSL::X509::CertificateError)
        from tmp/jruby_cert_sign_error.rb:14:in `(root)'

Cheers

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions