Re: rpki-client: warn on duplicate X509v3 extensions

2023-06-20 Thread Job Snijders
On Tue, Jun 20, 2023 at 08:58:23PM +0200, Theo Buehler wrote: > For some reason libcrypto doesn't check this part of RFC 5280, 4.2: A > certificate MUST NOT include more than one instance of a particular > extension. > > With the badCertSIA2x.cer from Ties's test artefacts, I get this > warning: >

rpki-client: warn on duplicate X509v3 extensions

2023-06-20 Thread Theo Buehler
For some reason libcrypto doesn't check this part of RFC 5280, 4.2: A certificate MUST NOT include more than one instance of a particular extension. With the badCertSIA2x.cer from Ties's test artefacts, I get this warning: rpki-client: badCertSIA2x.cer: RFC 5280 section 4.2: duplicate subjectInf