New issue
Advanced search Search tips

Issue 843735 link

Starred by 2 users

Issue metadata

Status: Available
Owner: ----
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug

Blocking:
issue 844210



Sign in to add a comment

Deprecate support for Netscape Server Gated Crypto

Project Member Reported by eroman@chromium.org, May 16 2018

Issue description

When verifying a server certificate, the extended key usage of the leaf certificate, and all the intermediates (  Issue 634442  ), must conform to serverAuth.

Currently Server Gated Crypto key usages [1] are accepted as equivalent to serverAuth, for legacy reasons.

For the builtin verifier, this legacy allowance is restricted to sha1 intermediates to prevent it from working with new certs (which seems sufficient from data on public certificates).

We should remove this legacy support for (Netscape) Server Gated Crypto altogether as these are not part of the RFC 5280 profile, or required by baseline requirements.

Attached is a sample chain with such an intermediate.

See also  Issue 733403  for more history.

[1] Netscape Server Gated Crypto (2.16.840.1.113730.4.1), Microsoft Server Gated Crypto (1.3.6.1.4.1.311.10.3.3)
 
api.holdsport.dk.pem
23.0 KB Download

Comment 1 by eroman@chromium.org, May 17 2018

Description: Show this description

Comment 2 by eroman@chromium.org, May 17 2018

Description: Show this description

Comment 3 by eroman@chromium.org, May 17 2018

Blocking: 844210

Sign in to add a comment