Skip to content

enforce pathLenConstraint when the last certificate is self-issued - #2491

Open
rootvector2 wants to merge 1 commit into
bcgit:mainfrom
rootvector2:cert-path-pathlen-self-issued
Open

rootvector2 wants to merge 1 commit into
bcgit:mainfrom
rootvector2:cert-path-pathlen-self-issued

Conversation

@rootvector2

Copy link
Copy Markdown
Contributor

BasicConstraintsValidation.validate checks a pathLenConstraint one certificate late: it decrements the remaining length on every certificate that is not self-issued, the last one included, and only throws once the value is already below zero. An intermediate that exceeds the limit is caught on the next non-self-issued certificate, and when there is none (the last certificate carries its issuer's own name, so subject equals issuer) the path validates. TA -> CA (pathLen 0) -> sub CA -> cert issued by the sub CA under its own name is accepted by CertPath.validate, while BC's PKIX CertPathValidator and the JDK's both reject it; found comparing the lightweight validator against RFC3280CertPathUtilities.prepareNextCertL.

The check now follows RFC 5280 sec. 6.1.4 (l): each non-self-issued certificate that is not the last in the path needs a remaining length above zero before it is decremented, using the context.isEndEntity() flag KeyUsageValidation already relies on. The excess is reported on the certificate that causes it, with the same message, and results for paths ending in a non-self-issued certificate are unchanged (the PKITS 4.6 cases still pass). BasicConstraintsTest gains the self-issued case, which fails without the change, and three permitted paths as controls.

AI tooling was used to help prepare this change.

@dghgit dghgit self-assigned this Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants