crl
crl::structure::crl-invalid-signature
Tests an invalid CRL that revokes the leaf but has a signature that does not
correspond to the root.
The CRL claims to be issued by the root CA (matching issuer name and AKI),
but is actually signed by a random ephemeral key.
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| FAILURE |
SERVER |
2024-01-01T00:00:00+00:00 |
has-crl |
undetermined |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
✅ |
CRL signature failure |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
✅ |
CRL signature failure |
libressl-4.2.1 |
✅ |
CRL signature failure |
openssl-1.1 |
✅ |
CRL signature failure |
libressl-4.1.2 |
✅ |
CRL signature failure |
libressl-3.9.2 |
✅ |
CRL signature failure |
libressl-4.0.1 |
✅ |
CRL signature failure |
openssl-3.5.8 |
✅ |
CRL signature failure |
openssl-3.0.22 |
✅ |
CRL signature failure |
libressl-4.3.2 |
✅ |
CRL signature failure |
openssl-3.4.7 |
✅ |
CRL signature failure |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
✅ |
CRL signature failure |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
✅ |
CRL signature failure |
rustls-webpki |
✅ |
InvalidCrlSignatureForPublicKey |
aws-lc-5.10.0 |
✅ |
CRL signature failure |
openssl-3.3.7 |
✅ |
CRL signature failure |
crl::structure::crl-wrong-signing-key
Tests that an invalid CRL signed by the wrong key is rejected.
Two root CAs are trusted. The CRL's issuer name matches root_ca_1 but the
CRL is signed with root_ca_2's key. Validators MUST reject the CRL because
the signature does not verify against root_ca_1's public key.
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| FAILURE |
SERVER |
2024-01-01T00:00:00+00:00 |
has-crl |
undetermined |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
✅ |
unable to get certificate CRL |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
✅ |
unable to get certificate CRL |
libressl-4.2.1 |
✅ |
unable to get certificate CRL |
openssl-1.1 |
✅ |
unable to get certificate CRL |
libressl-4.1.2 |
✅ |
unable to get certificate CRL |
libressl-3.9.2 |
✅ |
unable to get certificate CRL |
libressl-4.0.1 |
✅ |
unable to get certificate CRL |
openssl-3.5.8 |
✅ |
unable to get certificate CRL |
openssl-3.0.22 |
✅ |
unable to get certificate CRL |
libressl-4.3.2 |
✅ |
unable to get certificate CRL |
openssl-3.4.7 |
✅ |
unable to get certificate CRL |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
✅ |
unable to get certificate CRL |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
✅ |
unable to get certificate CRL |
rustls-webpki |
✅ |
InvalidCrlSignatureForPublicKey |
aws-lc-5.10.0 |
✅ |
unable to get certificate CRL |
openssl-3.3.7 |
✅ |
unable to get certificate CRL |
crl::structure::crl-empty
Tests that an valid but empty CRL (with no revocation entries) is accepted.
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| SUCCESS |
SERVER |
2024-01-01T00:00:00+00:00 |
has-crl |
undetermined |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
✅ |
N/A |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
✅ |
N/A |
libressl-4.2.1 |
✅ |
N/A |
openssl-1.1 |
✅ |
N/A |
libressl-4.1.2 |
✅ |
N/A |
libressl-3.9.2 |
✅ |
N/A |
libressl-4.0.1 |
✅ |
N/A |
openssl-3.5.8 |
✅ |
N/A |
openssl-3.0.22 |
✅ |
N/A |
libressl-4.3.2 |
✅ |
N/A |
openssl-3.4.7 |
✅ |
N/A |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
✅ |
N/A |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
✅ |
N/A |
rustls-webpki |
✅ |
N/A |
aws-lc-5.10.0 |
✅ |
N/A |
openssl-3.3.7 |
✅ |
N/A |
crl::structure::crl-very-large
Tests that a valid CRL with 10,000 revoked entries is accepted.
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| SUCCESS |
SERVER |
2024-01-01T00:00:00+00:00 |
has-crl |
undetermined |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
✅ |
N/A |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
✅ |
N/A |
libressl-4.2.1 |
✅ |
N/A |
openssl-1.1 |
✅ |
N/A |
libressl-4.1.2 |
✅ |
N/A |
libressl-3.9.2 |
✅ |
N/A |
libressl-4.0.1 |
✅ |
N/A |
openssl-3.5.8 |
✅ |
N/A |
openssl-3.0.22 |
✅ |
N/A |
libressl-4.3.2 |
✅ |
N/A |
openssl-3.4.7 |
✅ |
N/A |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
✅ |
N/A |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
✅ |
N/A |
rustls-webpki |
✅ |
N/A |
aws-lc-5.10.0 |
✅ |
N/A |
openssl-3.3.7 |
✅ |
N/A |
crl::structure::crl-duplicate-revoked-serial
Tests that a CRL with a duplicate revoked serial number is rejected.
For more context, see https://github.com/cabforum/servercert/issues/589.
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| FAILURE |
SERVER |
2024-01-01T00:00:00+00:00 |
has-crl |
undetermined |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
❌ (unexpected success) |
N/A |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
❌ (unexpected success) |
N/A |
libressl-4.2.1 |
❌ (unexpected success) |
N/A |
openssl-1.1 |
❌ (unexpected success) |
N/A |
libressl-4.1.2 |
❌ (unexpected success) |
N/A |
libressl-3.9.2 |
❌ (unexpected success) |
N/A |
libressl-4.0.1 |
❌ (unexpected success) |
N/A |
openssl-3.5.8 |
❌ (unexpected success) |
N/A |
openssl-3.0.22 |
❌ (unexpected success) |
N/A |
libressl-4.3.2 |
❌ (unexpected success) |
N/A |
openssl-3.4.7 |
❌ (unexpected success) |
N/A |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
❌ (unexpected success) |
N/A |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
❌ (unexpected success) |
N/A |
rustls-webpki |
❌ (unexpected success) |
N/A |
aws-lc-5.10.0 |
❌ (unexpected success) |
N/A |
openssl-3.3.7 |
❌ (unexpected success) |
N/A |
crl::structure::crl-unknown-critical-extension
Tests that a CRL with an unknown critical extension is rejected.
Per RFC 5280 5.2, CRLs that contain unknown critical extensions MUST NOT be
used to determine the revocation status of certificates.
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| FAILURE |
SERVER |
2024-01-01T00:00:00+00:00 |
has-crl |
undetermined |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
✅ |
unhandled critical CRL extension |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
✅ |
unhandled critical CRL extension |
libressl-4.2.1 |
✅ |
unhandled critical CRL extension |
openssl-1.1 |
✅ |
unhandled critical CRL extension |
libressl-4.1.2 |
✅ |
unhandled critical CRL extension |
libressl-3.9.2 |
✅ |
unhandled critical CRL extension |
libressl-4.0.1 |
✅ |
unhandled critical CRL extension |
openssl-3.5.8 |
✅ |
unhandled critical CRL extension |
openssl-3.0.22 |
✅ |
unhandled critical CRL extension |
libressl-4.3.2 |
✅ |
unhandled critical CRL extension |
openssl-3.4.7 |
✅ |
unhandled critical CRL extension |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
✅ |
unhandled critical CRL extension |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
✅ |
unhandled critical CRL extension |
rustls-webpki |
✅ |
CRL DER parse failed: UnsupportedCriticalExtension |
aws-lc-5.10.0 |
✅ |
unhandled critical CRL extension |
openssl-3.3.7 |
✅ |
unhandled critical CRL extension |
crl::structure::crl-unknown-noncritical-extension
Tests that a CRL with an unknown non-critical extension is accepted.
Per RFC 5280 5.2, unknown non-critical extensions MUST be ignored. The CRL
should be accepted by the validator and the chain should build.
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| SUCCESS |
SERVER |
2024-01-01T00:00:00+00:00 |
has-crl |
undetermined |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
✅ |
N/A |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
✅ |
N/A |
libressl-4.2.1 |
✅ |
N/A |
openssl-1.1 |
✅ |
N/A |
libressl-4.1.2 |
✅ |
N/A |
libressl-3.9.2 |
✅ |
N/A |
libressl-4.0.1 |
✅ |
N/A |
openssl-3.5.8 |
✅ |
N/A |
openssl-3.0.22 |
✅ |
N/A |
libressl-4.3.2 |
✅ |
N/A |
openssl-3.4.7 |
✅ |
N/A |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
✅ |
N/A |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
✅ |
N/A |
rustls-webpki |
✅ |
N/A |
aws-lc-5.10.0 |
✅ |
N/A |
openssl-3.3.7 |
✅ |
N/A |
crl::structure::entry-unknown-critical-extension
Tests that a CRL entry with an unknown critical extension is rejected.
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| FAILURE |
SERVER |
2024-01-01T00:00:00+00:00 |
has-crl |
undetermined |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
✅ |
unhandled critical CRL extension |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
✅ |
unhandled critical CRL extension |
libressl-4.2.1 |
✅ |
unhandled critical CRL extension |
openssl-1.1 |
✅ |
unhandled critical CRL extension |
libressl-4.1.2 |
✅ |
unhandled critical CRL extension |
libressl-3.9.2 |
✅ |
unhandled critical CRL extension |
libressl-4.0.1 |
✅ |
unhandled critical CRL extension |
openssl-3.5.8 |
✅ |
unhandled critical CRL extension |
openssl-3.0.22 |
✅ |
unhandled critical CRL extension |
libressl-4.3.2 |
✅ |
unhandled critical CRL extension |
openssl-3.4.7 |
✅ |
unhandled critical CRL extension |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
✅ |
unhandled critical CRL extension |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
✅ |
unhandled critical CRL extension |
rustls-webpki |
✅ |
CRL DER parse failed: UnsupportedCriticalExtension |
aws-lc-5.10.0 |
✅ |
unhandled critical CRL extension |
openssl-3.3.7 |
✅ |
unhandled critical CRL extension |
crl::structure::entry-unknown-noncritical-extension
Tests that a CRL entry with an unknown non-critical extension is accepted
and revokes the certificate.
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| FAILURE |
SERVER |
2024-01-01T00:00:00+00:00 |
has-crl |
undetermined |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
✅ |
certificate revoked |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
✅ |
certificate revoked |
libressl-4.2.1 |
✅ |
certificate revoked |
openssl-1.1 |
✅ |
certificate revoked |
libressl-4.1.2 |
✅ |
certificate revoked |
libressl-3.9.2 |
✅ |
certificate revoked |
libressl-4.0.1 |
✅ |
certificate revoked |
openssl-3.5.8 |
✅ |
certificate revoked |
openssl-3.0.22 |
✅ |
certificate revoked |
libressl-4.3.2 |
✅ |
certificate revoked |
openssl-3.4.7 |
✅ |
certificate revoked |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
✅ |
certificate revoked |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
✅ |
certificate revoked |
rustls-webpki |
✅ |
CertRevoked |
aws-lc-5.10.0 |
✅ |
certificate revoked |
openssl-3.3.7 |
✅ |
certificate revoked |
crl::revoked-certificate-with-crl
Tests a Certificate Revocation List (CRL) that revokes a certificate.
Produces a simple test case where a certificate has been revoked by the CA
through a CRL. The CA certificate and CRL are provided, and the leaf certificate
is expected to be rejected due to its revoked status.
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| FAILURE |
SERVER |
2024-01-01T00:00:00+00:00 |
has-crl |
high |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
✅ |
certificate revoked |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
✅ |
certificate revoked |
libressl-4.2.1 |
✅ |
certificate revoked |
openssl-1.1 |
✅ |
certificate revoked |
libressl-4.1.2 |
✅ |
certificate revoked |
libressl-3.9.2 |
✅ |
certificate revoked |
libressl-4.0.1 |
✅ |
certificate revoked |
openssl-3.5.8 |
✅ |
certificate revoked |
openssl-3.0.22 |
✅ |
certificate revoked |
libressl-4.3.2 |
✅ |
certificate revoked |
openssl-3.4.7 |
✅ |
certificate revoked |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
✅ |
certificate revoked |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
✅ |
certificate revoked |
rustls-webpki |
✅ |
CertRevoked |
aws-lc-5.10.0 |
✅ |
certificate revoked |
openssl-3.3.7 |
✅ |
certificate revoked |
crl::crlnumber-missing
Tests handling of a CRL that's missing the CRLNumber extension.
Per RFC 5280 5.2.3 this extension MUST be included in a CRL.
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| FAILURE |
SERVER |
1970-01-01T00:00:03+00:00 |
has-crl |
high |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
❌ (unexpected success) |
N/A |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
❌ (unexpected success) |
N/A |
libressl-4.2.1 |
❌ (unexpected success) |
N/A |
openssl-1.1 |
❌ (unexpected success) |
N/A |
libressl-4.1.2 |
❌ (unexpected success) |
N/A |
libressl-3.9.2 |
❌ (unexpected success) |
N/A |
libressl-4.0.1 |
❌ (unexpected success) |
N/A |
openssl-3.5.8 |
❌ (unexpected success) |
N/A |
openssl-3.0.22 |
❌ (unexpected success) |
N/A |
libressl-4.3.2 |
❌ (unexpected success) |
N/A |
openssl-3.4.7 |
❌ (unexpected success) |
N/A |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
❌ (unexpected success) |
N/A |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
❌ (unexpected success) |
N/A |
rustls-webpki |
❌ (unexpected success) |
N/A |
aws-lc-5.10.0 |
❌ (unexpected success) |
N/A |
openssl-3.3.7 |
❌ (unexpected success) |
N/A |
crl::certificate-not-on-crl
Tests a certificate that is not present on any of the CRLs (expected pass).
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| SUCCESS |
SERVER |
2024-01-01T00:00:00+00:00 |
has-crl |
high |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
✅ |
N/A |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
✅ |
N/A |
libressl-4.2.1 |
✅ |
N/A |
openssl-1.1 |
✅ |
N/A |
libressl-4.1.2 |
✅ |
N/A |
libressl-3.9.2 |
✅ |
N/A |
libressl-4.0.1 |
✅ |
N/A |
openssl-3.5.8 |
✅ |
N/A |
openssl-3.0.22 |
✅ |
N/A |
libressl-4.3.2 |
✅ |
N/A |
openssl-3.4.7 |
✅ |
N/A |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
✅ |
N/A |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
✅ |
N/A |
rustls-webpki |
✅ |
N/A |
aws-lc-5.10.0 |
✅ |
N/A |
openssl-3.3.7 |
✅ |
N/A |
crl::certificate-serial-on-crl-different-issuer
Tests a certificate whose serial number is found on a CRL, but that CRL
has a different issuer than the certificate (expected pass).
Produces a test case where a certificate's serial number appears on a CRL,
but the CRL is issued by a different CA than the one that issued the
certificate. The certificate should be accepted since the CRL from a
different issuer should not affect this certificate's validity.
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| SUCCESS |
SERVER |
2024-01-01T00:00:00+00:00 |
has-crl |
high |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
✅ |
N/A |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
✅ |
N/A |
libressl-4.2.1 |
✅ |
N/A |
openssl-1.1 |
✅ |
N/A |
libressl-4.1.2 |
✅ |
N/A |
libressl-3.9.2 |
✅ |
N/A |
libressl-4.0.1 |
✅ |
N/A |
openssl-3.5.8 |
✅ |
N/A |
openssl-3.0.22 |
✅ |
N/A |
libressl-4.3.2 |
✅ |
N/A |
openssl-3.4.7 |
✅ |
N/A |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
✅ |
N/A |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
✅ |
N/A |
rustls-webpki |
✅ |
N/A |
aws-lc-5.10.0 |
✅ |
N/A |
openssl-3.3.7 |
✅ |
N/A |
crl::crlnumber-critical
Tests handling of a CRL that has a critical CRLNumber extension.
Per RFC 5280 5.2.3, the CRLNumber extension is mandatory but MUST
be marked as non-critical.
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| FAILURE |
SERVER |
1970-01-01T00:00:03+00:00 |
has-crl |
high |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
✅ |
unhandled critical CRL extension |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
✅ |
unhandled critical CRL extension |
libressl-4.2.1 |
✅ |
unhandled critical CRL extension |
openssl-1.1 |
✅ |
unhandled critical CRL extension |
libressl-4.1.2 |
✅ |
unhandled critical CRL extension |
libressl-3.9.2 |
✅ |
unhandled critical CRL extension |
libressl-4.0.1 |
✅ |
unhandled critical CRL extension |
openssl-3.5.8 |
✅ |
unhandled critical CRL extension |
openssl-3.0.22 |
✅ |
unhandled critical CRL extension |
libressl-4.3.2 |
✅ |
unhandled critical CRL extension |
openssl-3.4.7 |
✅ |
unhandled critical CRL extension |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
✅ |
unhandled critical CRL extension |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
✅ |
unhandled critical CRL extension |
rustls-webpki |
❌ (unexpected success) |
N/A |
aws-lc-5.10.0 |
✅ |
unhandled critical CRL extension |
openssl-3.3.7 |
✅ |
unhandled critical CRL extension |
crl::issuer-missing-crlsign
Tests CRL validation when the CA issuer has a keyUsage extension with only
keyCertSign set (no cRLSign).
Per RFC 5280 Section 4.2.1.3, if the keyUsage extension is present in a CA
certificate, the cRLSign bit MUST be set if the CA will be issuing CRLs.
A CRL signed by a CA without the cRLSign bit should be rejected.
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| FAILURE |
SERVER |
2024-01-01T00:00:00+00:00 |
has-crl |
high |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
✅ |
key usage does not include CRL signing |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
✅ |
key usage does not include CRL signing |
libressl-4.2.1 |
✅ |
key usage does not include CRL signing |
openssl-1.1 |
✅ |
key usage does not include CRL signing |
libressl-4.1.2 |
✅ |
key usage does not include CRL signing |
libressl-3.9.2 |
✅ |
key usage does not include CRL signing |
libressl-4.0.1 |
✅ |
key usage does not include CRL signing |
openssl-3.5.8 |
✅ |
key usage does not include CRL signing |
openssl-3.0.22 |
✅ |
key usage does not include CRL signing |
libressl-4.3.2 |
✅ |
key usage does not include CRL signing |
openssl-3.4.7 |
✅ |
key usage does not include CRL signing |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
✅ |
key usage does not include CRL signing |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
✅ |
key usage does not include CRL signing |
rustls-webpki |
❌ (unexpected success) |
N/A |
aws-lc-5.10.0 |
✅ |
key usage does not include CRL signing |
openssl-3.3.7 |
✅ |
key usage does not include CRL signing |
crl::issuer-no-keyusage-extension
Tests CRL validation when the CA issuer has no keyUsage extension.
Per RFC 5280 Section 6.3.3(f), the CRL validation algorithm states:
"If a key usage extension is present in the CRL issuer's certificate,
verify that the cRLSign bit is set." This conditional check means that
when keyUsage is absent, there is no cRLSign verification to perform.
Note: RFC 5280 Section 4.2.1.3 states that "Conforming CAs MUST include
this extension in certificates that contain public keys that are used to
validate digital signatures on other public key certificates or CRLs."
However, this is a certificate issuance requirement, not a validation
requirement. The validation algorithm in Section 6.3.3(f) explicitly uses
conditional language ("If... is present").
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| SUCCESS |
SERVER |
2024-01-01T00:00:00+00:00 |
has-crl |
high |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
❌ (unexpected failure) |
CA cert does not include key usage extension |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
❌ (unexpected failure) |
CA cert does not include key usage extension |
libressl-4.2.1 |
✅ |
N/A |
openssl-1.1 |
✅ |
N/A |
libressl-4.1.2 |
✅ |
N/A |
libressl-3.9.2 |
✅ |
N/A |
libressl-4.0.1 |
✅ |
N/A |
openssl-3.5.8 |
❌ (unexpected failure) |
CA cert does not include key usage extension |
openssl-3.0.22 |
❌ (unexpected failure) |
CA cert does not include key usage extension |
libressl-4.3.2 |
✅ |
N/A |
openssl-3.4.7 |
❌ (unexpected failure) |
CA cert does not include key usage extension |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
❌ (unexpected failure) |
CA cert does not include key usage extension |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
✅ |
N/A |
rustls-webpki |
✅ |
N/A |
aws-lc-5.10.0 |
✅ |
N/A |
openssl-3.3.7 |
❌ (unexpected failure) |
CA cert does not include key usage extension |
crl::issuer-valid-crlsign-and-keycertsign
Tests CRL validation when the CA issuer has a keyUsage extension with both
keyCertSign and cRLSign bits set.
This is the standard configuration for a CA that issues both certificates
and CRLs. The CRL should be accepted.
| Expected result |
Validation kind |
Validation time |
Features |
Importance |
Conflicts |
| SUCCESS |
SERVER |
2024-01-01T00:00:00+00:00 |
has-crl |
high |
N/A |
| Harness |
Result |
Context |
openssl-3.6.4 |
✅ |
N/A |
gocryptox509-go1.26.8 |
🚧 |
CRLs not supported |
openssl-4.0.2 |
✅ |
N/A |
libressl-4.2.1 |
✅ |
N/A |
openssl-1.1 |
✅ |
N/A |
libressl-4.1.2 |
✅ |
N/A |
libressl-3.9.2 |
✅ |
N/A |
libressl-4.0.1 |
✅ |
N/A |
openssl-3.5.8 |
✅ |
N/A |
openssl-3.0.22 |
✅ |
N/A |
libressl-4.3.2 |
✅ |
N/A |
openssl-3.4.7 |
✅ |
N/A |
certvalidator-0.11.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
openssl-3.2.6 |
✅ |
N/A |
pyca-cryptography-50.0.1 |
🚧 |
testcase skipped (explicit unsupported feature) |
gnutls-certtool-3.8.3 |
🚧 |
CRLs not supported yet |
boringssl-legacy-43 |
✅ |
N/A |
rustls-webpki |
✅ |
N/A |
aws-lc-5.10.0 |
✅ |
N/A |
openssl-3.3.7 |
✅ |
N/A |