Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-65345

certutil -V exitcode on large certs changed between 9 and 10 after switching to pkix

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Minor Minor
    • None
    • rhel-8.8.0.z, rhel-8.10.z, rhel-9.2.0.z, rhel-9.4.z, rhel-9.5.z
    • nss
    • None
    • No
    • Low
    • rhel-sst-security-crypto
    • ssg_security
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None

      What were you trying to do that didn't work?

      Verifying a cert chain using 16K RSA keys.

      What is the impact of this issue to you?

      None.

      Please provide the package NVR for which the bug is seen:

      nss-3.101.0-7.el9_2

      How reproducible is this bug?:

      reliably

      Steps to reproduce

      mkdir nssdb
      certutil -d nssdb -N --empty-password
      certutil -d nssdb -A -n ca -t 'cCT,,' -a -i ca.pem
      certutil -d nssdb -A -n server -t ',,' -a -i server.pem
      certutil -d nssdb -V -n server -l -e -u V
      echo $?
      

      Expected results

      Complains about the cert chain, errors out

      Actual results

      nss-3.101.0-7.el9_2: prints server : Peer's certificate has an invalid signature., exit code is 0
      nss-3.101.0-7.el10; prints ca : Peer's certificate has an invalid signature., exit code is 255

      Comments

      rrelyea@redhat.com says it's expected that pkix validates root-to-leaf, which is fine by me. The change in the retcode is more suspicious, but it's a change for the better, so filing it as an issue against 9.

        1. ca.pem
          23 kB
        2. server.pem
          23 kB

              rrelyea@redhat.com Robert Relyea
              asosedki@redhat.com Alexander Sosedkin
              Robert Relyea Robert Relyea
              Alexander Sosedkin Alexander Sosedkin
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: