Skip to content

Tolerate certificate chain errors related to private CAs - #2617

Closed
hxmf wants to merge 1 commit into
yhirose:masterfrom
hxmf:fix-handling-of-private-root-CAs
Closed

hxmf wants to merge 1 commit into
yhirose:masterfrom
hxmf:fix-handling-of-private-root-CAs

Conversation

@hxmf

@hxmf hxmf commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

For a private CA where unavailable revocation information is acceptable, ignore the "unknown" and "offline" errors while preserving all other certificate errors.

For a private CA where unavailable revocation information is acceptable,
ignore the "unknown" and "offline" errors while preserving all other
certificate errors.
@yhirose

yhirose commented Oct 8, 2026

Copy link
Copy Markdown
Owner

Thank you for finding this. The problem is real: on Windows, a server certificate with an unknown revocation status has been rejected since v0.31.0, although the chain policy check was already told to ignore it.

I am fixing it in #2618 in a different way. It removes the trust status pre-check, so that CertVerifyCertificateChainPolicy() is the only place that judges the chain and the policy is stated once. The case you describe, a private CA without revocation information, is accepted with that change, and a revoked certificate is still rejected.

Closing in favor of #2618.

@yhirose yhirose closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants